kevmap

Log sources › WinEventLog:Application

WinEventLog:Application

Inverted view: what can be detected if this is the log you have. Office Suite, Windows

20
channels
22
analytics
22
techniques
98
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API call to AddMonitor invoked by non-installer process DC0021 OS API Execution AN0580 1
Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events DC0038 Application Log Content AN0498 1
CLR Assembly creation, loading, or modification logs via MSSQL CLR integration DC0016 Module Load AN0511 1
EventCode=1000 DC0038 Application Log Content AN0540 AN0797 AN0850 AN1314 4
Exchange Transport Service loads unusual .NET assembly or errors upon transport agent execution DC0038 Application Log Content AN0472 1
Exchange logs or header artifacts DC0038 Application Log Content AN1309 1
High-frequency errors or hangs from resource-intensive application components (e.g., .NET, IIS, Office Suite) DC0038 Application Log Content AN1165 1
Office Add-in load errors, abnormal loading context, or unsigned add-in warnings DC0038 Application Log Content AN0138 1
Outlook errors loading or processing custom form templates DC0038 Application Log Content AN0085 1
Outlook logs indicating failure to load or render HTML page in Home Page view DC0038 Application Log Content AN0502 1
Outlook rule creation, form load, or homepage redirection DC0038 Application Log Content AN1116 1
Outlook rule execution failure or abnormal rule execution context DC0038 Application Log Content AN0263 1
SCCM, Intune logs DC0038 Application Log Content AN0623 1
Service crash, unhandled exception, or application hang warnings for critical services (e.g., IIS, DNS, SQL Server) DC0038 Application Log Content AN0584 1
Stored procedure creation, modification, or xp_cmdshell invocation via SQL logs or SQL Server auditing DC0029 Script Execution AN0511 1
Unexpected spikes in request volume, application-level errors, or thread pool exhaustion in web or API logs DC0038 Application Log Content AN0489 1
Unexpected web application errors or CMS logs showing modification to index.html, default.aspx, or other public-facing files DC0038 Application Log Content AN0662 1
Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs DC0038 Application Log Content AN1507 1
VPN, Citrix, or remote access gateway logs showing external IP addresses DC0038 Application Log Content AN1004 1
WMI Object Creation Events DC0008 WMI Creation AN0973 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 T1499.004 Mapped
CVE-2015-5119Adobe Flash Player T1203 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2018-4939Adobe ColdFusion T1133 T1203 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1133 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1133 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1133 Mapped
CVE-2019-5591Fortinet FortiOS T1133 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2020-1472Microsoft Netlogon T1133 Mapped
CVE-2020-25506D-Link DNS-320 Device T1133 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 Mapped
CVE-2020-5902F5 BIG-IP T1133 Stale
CVE-2020-8515DrayTek Multiple Vigor Routers T1133 Mapped
CVE-2021-1497Cisco HyperFlex HX T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1133 Mapped
CVE-2021-21148Google Chromium V8 T1203 Mapped
CVE-2021-21166Google Chromium T1203 Mapped
CVE-2021-21206Google Chromium Blink T1203 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1133 Mapped
CVE-2021-26855Microsoft Exchange Server T1133 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1203 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1499 Mapped
CVE-2021-37975Google Chromium V8 T1203 Mapped
CVE-2021-39144XStream XStream T1203 Mapped
CVE-2021-45382D-Link Multiple Routers T1499.002 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1133 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-23748Audinate Dante Discovery T1203 Mapped
CVE-2022-26258D-Link DIR-820L T1499.002 Mapped
CVE-2022-29303SolarView Compact T1505 Mapped
CVE-2022-41128Microsoft Windows T1203 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1203 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1133 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 Mapped
CVE-2023-23397Microsoft Office T1203 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 Mapped
CVE-2023-27532Veeam Backup & Replication T1133 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-36844Juniper Junos OS T1203 Mapped
CVE-2023-38831RARLAB WinRAR T1204 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1133 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 Mapped
CVE-2023-48365Qlik Sense T1133 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 T1203 Mapped
CVE-2024-26169Microsoft Windows T1203 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1114 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped
CVE-2024-45195Apache OFBiz T1133 T1203 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 T1203 Mapped
CVE-2024-54085AMI MegaRAC SPx T1499 Mapped
CVE-2025-24016Wazuh Wazuh Server T1203 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24993Microsoft Windows T1203 T1204 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1203 Mapped
CVE-2025-27363FreeType FreeType T1499.004 Mapped
CVE-2025-2783Google Chromium Mojo T1203 Mapped
CVE-2025-30397Microsoft Windows T1203 Mapped
CVE-2025-30406Gladinet CentreStack T1203 Mapped
CVE-2025-31200Apple Multiple Products T1203 Stale
CVE-2025-31201Apple Multiple Products T1203 Stale
CVE-2025-3248Langflow Langflow T1203 Mapped
CVE-2025-32756Fortinet Multiple Products T1133 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1203 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped
CVE-2025-42999SAP NetWeaver T1203 Mapped
CVE-2025-43200Apple Multiple Products T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1203 Mapped
CVE-2025-49706Microsoft SharePoint T1505 Mapped
CVE-2025-5419Google Chromium V8 T1189 T1203 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1203 Mapped
CVE-2025-6554Google Chromium V8 T1189 T1203 Mapped
CVE-2025-6558Google Chromium T1189 T1203 Mapped