kevmap

Log sources › saas:auth

saas:auth

Inverted view: what can be detected if this is the log you have. Identity Provider, SaaS

5
channels
5
analytics
5
techniques
21
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API requests made with tokens not associated with expected user logins DC0007 Web Credential Usage AN0722 1
Login, TokenGranted: Discovery actions tied to anomalous login sessions or tokens DC0067 Logon Session Creation AN1130 1
LoginSuccess, APIKeyUse, AdminAction DC0067 Logon Session Creation AN0020 1
Refresh token issuance or refresh token usage from new IPs or user agents DC0013 User Account Metadata AN0501 1
signin_failed DC0002 User Account Authentication AN1343 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.007 Cloud Serviceslateral movement10
T1110.003 Password Sprayingcredential access00
T1189 Drive-by Compromiseinitial access321
T1526 Cloud Service Discoverydiscovery30
T1606 Forge Web Credentialscredential access10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped