kevmap

Log sources › NSM:Firewall

NSM:Firewall

Inverted view: what can be detected if this is the log you have. ESXi, Network Devices, Windows, macOS

12
channels
12
analytics
10
techniques
6
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Anomalous TCP SYN or ACK spikes from specific source or interface DC0085 Network Traffic Content AN1014 1
High rate of inbound TCP SYN or ACK packets with missing 3-way handshake completion DC0085 Network Traffic Content AN1012 1
ICMP/UDP protocol anomaly DC0085 Network Traffic Content AN1258 1
Outbound Connections DC0082 Network Connection Creation AN0161 1
Outbound connections to 139/445 to multiple destinations DC0078 Network Traffic Flow AN0515 1
Outbound encrypted traffic DC0085 Network Traffic Content AN1024 1
Policy Change / Rule Update DC0051 Firewall Rule Modification AN1233 1
TLS/HTTP inspection DC0085 Network Traffic Content AN0567 1
inbound connection to port 5900 DC0078 Network Traffic Flow AN0506 1
pf firewall logs DC0078 Network Traffic Flow AN1231 1
proxy or TLS inspection logs DC0082 Network Connection Creation AN0285 1
rule_modification: New or modified firewall rules related to wireless interfaces DC0051 Firewall Rule Modification AN1479 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.005 VNClateral movement10
T1056 Input Capturecollection, credential access23
T1090 Proxycommand and control223
T1090.003 Multi-hop Proxycommand and control30
T1090.004 Domain Frontingcommand and control10
T1095 Non-Application Layer Protocolcommand and control30
T1102.001 Dead Drop Resolvercommand and control40
T1135 Network Share Discoverydiscovery70
T1499.001 OS Exhaustion Floodimpact10
T1669 Wi-Fi Networksinitial access00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1090 Mapped
CVE-2021-26855Microsoft Exchange Server T1090 Mapped
CVE-2024-42009Roundcube Webmail T1056 Mapped