kevmap

Log sources › NSM:Connections

NSM:Connections

Inverted view: what can be detected if this is the log you have. Identity Provider, Linux, Network Devices, Windows, macOS

24
channels
25
analytics
23
techniques
141
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Abnormal certificate chains or non-standard ports carrying TLS DC0085 Network Traffic Content AN0763 1
Accepted password or publickey for user from remote IP DC0002 User Account Authentication AN0335 1
Accepted publickey for user from unusual IP or without tty DC0067 Logon Session Creation AN0955 1
Failed password or accepted password for SSH users DC0038 Application Log Content AN1005 1
Inbound on ports 5985/5986 DC0078 Network Traffic Flow AN1313 1
Internal connection logging DC0078 Network Traffic Flow AN0205 1
Mismatch between recorded user logon and active sessions (e.g., wtmp/utmp entries without corresponding authentication in auth.log) DC0067 Logon Session Creation AN0217 1
Missing new login event but session activity continues DC0067 Logon Session Creation AN0710 1
New outbound connection from Safari/Chrome/Firefox/Word DC0082 Network Connection Creation AN0180 1
Outbound Connection DC0078 Network Traffic Flow AN1229 1
Outbound connection after script or installer launch DC0082 Network Connection Creation AN2036 AN2037 1
Outbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous ports DC0082 Network Connection Creation AN0499 1
Pre-authentication keys generated or token signing anomalies DC0007 Web Credential Usage AN0718 1
PushNotificationSent DC0038 Application Log Content AN0449 1
Repeated failed authentication attempts or replay patterns DC0002 User Account Authentication AN0494 1
Successful login without expected MFA challenge DC0002 User Account Authentication AN0546 1
Successful sudo or ssh from unknown IPs DC0088 Logon Session Metadata AN1623 1
Symmetric encryption detected without TLS handshake sequence DC0085 Network Traffic Content AN0404 1
TLS handshake + HTTP headers DC0085 Network Traffic Content AN0564 1
Unusual POST requests to admin or upload endpoints DC0085 Network Traffic Content AN1622 1
new connections from exploited lineage DC0078 Network Traffic Flow AN0799 1
simultaneous or anomalous logon sessions across multiple systems DC0067 Logon Session Creation AN1250 1
sshd or PAM logins DC0002 User Account Authentication AN1544 1
web domain alerts DC0082 Network Connection Creation AN0102 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.006 Windows Remote Managementlateral movement110
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.004 Domain Frontingcommand and control10
T1102.002 Bidirectional Communicationcommand and control40
T1133 External Remote Servicespersistence, initial access2025
T1189 Drive-by Compromiseinitial access321
T1203 Exploitation for Client Executionexecution3543
T1204.001 Malicious Linkexecution411
T1212 Exploitation for Credential Accesscredential access54
T1491.002 External Defacementimpact01
T1531 Account Access Removalimpact91
T1550 Use Alternate Authentication Materiallateral movement50
T1556.003 Pluggable Authentication Modulesdefense impairment, persistence, credential access00
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1563 Remote Service Session Hijackinglateral movement00
T1563.001 SSH Hijackinglateral movement00
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1606 Forge Web Credentialscredential access10
T1621 Multi-Factor Authentication Request Generationcredential access20
T1684 Social Engineeringstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-0767Adobe Flash Player T1204.001 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-5119Adobe Flash Player T1203 T1204.001 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2018-15961Adobe ColdFusion T1491.002 Mapped
CVE-2018-4939Adobe ColdFusion T1133 T1203 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1133 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1133 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1078 Mapped
CVE-2019-13608Citrix StoreFront Server T1078 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 T1133 Mapped
CVE-2019-5591Fortinet FortiOS T1133 Mapped
CVE-2020-1472Microsoft Netlogon T1133 Mapped
CVE-2020-25506D-Link DNS-320 Device T1133 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1204.001 Mapped
CVE-2020-5902F5 BIG-IP T1133 Stale
CVE-2020-8515DrayTek Multiple Vigor Routers T1133 Mapped
CVE-2021-1497Cisco HyperFlex HX T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1133 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1078 Mapped
CVE-2021-21148Google Chromium V8 T1203 Mapped
CVE-2021-21166Google Chromium T1203 Mapped
CVE-2021-21206Google Chromium Blink T1203 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1090 T1133 Mapped
CVE-2021-26855Microsoft Exchange Server T1090 T1133 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1203 Mapped
CVE-2021-36934Microsoft Windows T1078 Mapped
CVE-2021-37975Google Chromium V8 T1203 Mapped
CVE-2021-39144XStream XStream T1203 Mapped
CVE-2021-40449Microsoft Windows T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1573.001 Mapped
CVE-2021-41379Microsoft Windows T1078 Mapped
CVE-2021-42321Microsoft Exchange T1078 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1573.001 Mapped
CVE-2022-1040Sophos Firewall T1078 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1133 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-21919Microsoft Windows T1078 Mapped
CVE-2022-21971Microsoft Windows T1204.001 Mapped
CVE-2022-21999Microsoft Windows T1078 Mapped
CVE-2022-22047Microsoft Windows T1078 Mapped
CVE-2022-22718Microsoft Windows T1078 Mapped
CVE-2022-22948VMware vCenter Server T1078 T1212 Mapped
CVE-2022-23131Zabbix Frontend T1078 Mapped
CVE-2022-23748Audinate Dante Discovery T1203 Mapped
CVE-2022-24521Microsoft Windows T1078 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1204.001 Mapped
CVE-2022-26500Veeam Backup & Replication T1078 Mapped
CVE-2022-26904Microsoft Windows T1078 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-37969Microsoft Windows T1078 Mapped
CVE-2022-41073Microsoft Windows T1078 Mapped
CVE-2022-41082Microsoft Exchange Server T1078 Mapped
CVE-2022-41125Microsoft Windows T1078 Mapped
CVE-2022-41128Microsoft Windows T1203 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1203 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1078 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1078 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 T1133 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1078 Mapped
CVE-2023-20867VMware Tools T1078 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 Mapped
CVE-2023-21674Microsoft Windows T1078 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1078 Mapped
CVE-2023-22952SugarCRM Multiple Products T1078 Stale
CVE-2023-23397Microsoft Office T1078 T1203 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 Mapped
CVE-2023-27524Apache Superset T1078 Mapped
CVE-2023-27532Veeam Backup & Replication T1133 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1078 Mapped
CVE-2023-28252Microsoft Windows T1078 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-34362Progress MOVEit Transfer T1531 Mapped
CVE-2023-36844Juniper Junos OS T1203 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1078 T1133 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1078 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 Mapped
CVE-2023-48365Qlik Sense T1133 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 Mapped
CVE-2023-5631Roundcube Webmail T1204.001 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 T1203 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1078 Mapped
CVE-2024-20399Cisco NX-OS T1078 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 Mapped
CVE-2024-26169Microsoft Windows T1203 Mapped
CVE-2024-37085VMware ESXi T1078 Mapped
CVE-2024-38112Microsoft Windows T1189 T1204.001 Mapped
CVE-2024-45195Apache OFBiz T1133 T1203 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 T1203 Mapped
CVE-2024-53704SonicWall SonicOS T1212 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1078 Mapped
CVE-2024-57968Advantive VeraCore T1078 Mapped
CVE-2025-24016Wazuh Wazuh Server T1078 T1203 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24993Microsoft Windows T1203 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1203 Mapped
CVE-2025-2783Google Chromium Mojo T1203 Mapped
CVE-2025-30397Microsoft Windows T1203 Mapped
CVE-2025-30406Gladinet CentreStack T1203 Mapped
CVE-2025-31161CrushFTP CrushFTP T1078 Mapped
CVE-2025-31200Apple Multiple Products T1203 Stale
CVE-2025-31201Apple Multiple Products T1203 Stale
CVE-2025-3248Langflow Langflow T1203 Mapped
CVE-2025-32756Fortinet Multiple Products T1133 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1203 Mapped
CVE-2025-42999SAP NetWeaver T1203 Mapped
CVE-2025-43200Apple Multiple Products T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1203 Mapped
CVE-2025-48927TeleMessage TM SGNL T1212 Mapped
CVE-2025-48928TeleMessage TM SGNL T1212 Mapped
CVE-2025-5419Google Chromium V8 T1189 T1203 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1203 Mapped
CVE-2025-6554Google Chromium V8 T1189 T1203 Mapped
CVE-2025-6558Google Chromium T1189 T1203 Mapped