Log sources › NSM:Connections
NSM:Connections
Inverted view: what can be detected if this is the log you have. Identity Provider, Linux, Network Devices, Windows, macOS
24
channels
25
analytics
23
techniques
141
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Abnormal certificate chains or non-standard ports carrying TLS |
DC0085 Network Traffic Content | AN0763 | 1 |
Accepted password or publickey for user from remote IP |
DC0002 User Account Authentication | AN0335 | 1 |
Accepted publickey for user from unusual IP or without tty |
DC0067 Logon Session Creation | AN0955 | 1 |
Failed password or accepted password for SSH users |
DC0038 Application Log Content | AN1005 | 1 |
Inbound on ports 5985/5986 |
DC0078 Network Traffic Flow | AN1313 | 1 |
Internal connection logging |
DC0078 Network Traffic Flow | AN0205 | 1 |
Mismatch between recorded user logon and active sessions (e.g., wtmp/utmp entries without corresponding authentication in auth.log) |
DC0067 Logon Session Creation | AN0217 | 1 |
Missing new login event but session activity continues |
DC0067 Logon Session Creation | AN0710 | 1 |
New outbound connection from Safari/Chrome/Firefox/Word |
DC0082 Network Connection Creation | AN0180 | 1 |
Outbound Connection |
DC0078 Network Traffic Flow | AN1229 | 1 |
Outbound connection after script or installer launch |
DC0082 Network Connection Creation | AN2036 AN2037 | 1 |
Outbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous ports |
DC0082 Network Connection Creation | AN0499 | 1 |
Pre-authentication keys generated or token signing anomalies |
DC0007 Web Credential Usage | AN0718 | 1 |
PushNotificationSent |
DC0038 Application Log Content | AN0449 | 1 |
Repeated failed authentication attempts or replay patterns |
DC0002 User Account Authentication | AN0494 | 1 |
Successful login without expected MFA challenge |
DC0002 User Account Authentication | AN0546 | 1 |
Successful sudo or ssh from unknown IPs |
DC0088 Logon Session Metadata | AN1623 | 1 |
Symmetric encryption detected without TLS handshake sequence |
DC0085 Network Traffic Content | AN0404 | 1 |
TLS handshake + HTTP headers |
DC0085 Network Traffic Content | AN0564 | 1 |
Unusual POST requests to admin or upload endpoints |
DC0085 Network Traffic Content | AN1622 | 1 |
new connections from exploited lineage |
DC0078 Network Traffic Flow | AN0799 | 1 |
simultaneous or anomalous logon sessions across multiple systems |
DC0067 Logon Session Creation | AN1250 | 1 |
sshd or PAM logins |
DC0002 User Account Authentication | AN1544 | 1 |
web domain alerts |
DC0082 Network Connection Creation | AN0102 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1204.001 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1203 T1204.001 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1491.002 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 T1203 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1133 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1133 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1078 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1078 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 T1133 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1133 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1133 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1133 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1204.001 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1133 | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1133 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1078 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1203 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1090 T1133 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1090 T1133 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1203 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1203 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1573.001 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1078 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1573.001 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1078 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1133 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1078 T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1204.001 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1078 T1212 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1078 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1203 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1204.001 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1078 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1204.001 | Mapped |
| CVE-2022-3075 | Google Chromium Mojo | T1204.001 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1078 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1203 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1203 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1078 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1078 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1078 T1133 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1078 | Mapped |
| CVE-2023-20867 | VMware Tools | T1078 | Mapped |
| CVE-2023-2136 | Google Chromium Skia | T1204.001 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1078 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1078 | Stale |
| CVE-2023-23397 | Microsoft Office | T1078 T1203 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-27524 | Apache Superset | T1078 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1133 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1078 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1531 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1203 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1078 T1133 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1078 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1078 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1133 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1204.001 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1204.001 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 T1203 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1078 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1078 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1078 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1203 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1078 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 T1204.001 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1133 T1203 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1212 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1078 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1078 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1078 T1203 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1203 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1203 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1078 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-3248 | Langflow Langflow | T1203 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1133 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1203 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1203 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1203 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 T1203 | Mapped |