kevmap

Log sources › WinEventLog:PowerShell

WinEventLog:PowerShell

Inverted view: what can be detected if this is the log you have. Office Suite, Windows

13
channels
65
analytics
64
techniques
26
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
CmdletName: Get-Recipient, Get-User DC0064 Command Execution AN1089 1
CommandLine=copy-item or robocopy from UNC path DC0064 Command Execution AN0194 1
EventCode=400, 403 DC0034 Process Metadata AN1252 1
EventCode=4103, 4104, 4105, 4106 DC0029 Script Execution
DC0064 Command Execution
AN0037 AN0089 AN0131 AN0152 AN0182 AN0254 AN0271 AN0274 AN0286 AN0345 AN0363 AN0388 AN0392 AN0430 AN0455 AN0469 AN0472 AN0507 AN0513 AN0551 AN0559 AN0589 AN0622 AN0641 AN0737 AN0834 AN0903 AN0927 AN0932 AN0962 AN1015 AN1025 AN1028 AN1177 AN1207 AN1220 AN1252 AN1280 AN1288 AN1305 AN1309 AN1325 AN1440 AN1448 AN1452 AN1461 AN1464 AN1551 AN1557 AN1567 AN1589 AN1621 AN2030 AN2063 54
Exchange Cmdlets DC0064 Command Execution AN0740 1
Execution of 'Get-WmiObject Win32_Product' or similar PowerShell cmdlets DC0064 Command Execution AN1100 1
Execution of Microsoft script to enumerate custom forms in Outlook mailbox DC0064 Command Execution AN0085 1
Execution of PowerShell script to enumerate or remove malicious Home Page folder config DC0064 Command Execution AN0502 1
Execution of PowerShell without -NoProfile flag DC0064 Command Execution AN1245 1
Get-ADTrust|GetAllTrustRelationships DC0064 Command Execution AN0016 1
PowerShell launched from outlook.exe or triggered without user invocation DC0064 Command Execution AN0263 1
Scripts with references to XML parsing, AES decryption, or gpprefdecrypt logic DC0029 Script Execution AN1075 1
Set-ADUser or Set-ADAuthenticationPolicy with MFA attributes disabled DC0029 Script Execution AN0543 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1007 System Service Discoverydiscovery111
T1010 Application Window Discoverydiscovery10
T1012 Query Registrydiscovery140
T1016 System Network Configuration Discoverydiscovery121
T1016.001 Internet Connection Discoverydiscovery00
T1016.002 Wi-Fi Discoverydiscovery00
T1027.018 Invisible Unicodestealth00
T1033 System Owner/User Discoverydiscovery302
T1036.001 Invalid Code Signaturestealth00
T1036.002 Right-to-Left Overridestealth30
T1049 System Network Connections Discoverydiscovery91
T1056.002 GUI Input Capturecollection, credential access30
T1059.001 PowerShellexecution2201
T1069 Permission Groups Discoverydiscovery31
T1069.002 Domain Groupsdiscovery150
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1070.005 Network Share Connection Removalstealth40
T1070.008 Clear Mailbox Datastealth20
T1074.002 Remote Data Stagingcollection00
T1082 System Information Discoverydiscovery337
T1087.002 Domain Accountdiscovery215
T1087.003 Email Accountdiscovery00
T1087.004 Cloud Accountdiscovery30
T1114 Email Collectioncollection43
T1114.002 Remote Email Collectioncollection01
T1114.003 Email Forwarding Rulecollection60
T1124 System Time Discoverydiscovery30
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1135 Network Share Discoverydiscovery70
T1137.003 Outlook Formspersistence10
T1137.004 Outlook Home Pagepersistence00
T1137.005 Outlook Rulespersistence00
T1197 BITS Jobsstealth, persistence, execution160
T1201 Password Policy Discoverydiscovery60
T1204.004 Malicious Copy and Pasteexecution60
T1205 Traffic Signalingstealth, persistence, command and control00
T1216 System Script Proxy Executionstealth130
T1216.001 PubPrnstealth20
T1216.002 SyncAppvPublishingServerstealth00
T1217 Browser Information Discoverydiscovery41
T1218.003 CMSTPstealth70
T1218.004 InstallUtilstealth00
T1218.009 Regsvcs/Regasmstealth40
T1218.013 Mavinjectstealth20
T1218.014 MMCstealth20
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.001 Windows Permissionsdefense impairment50
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1482 Domain Trust Discoverydiscovery172
T1505.002 Transport Agentpersistence30
T1518 Software Discoverydiscovery40
T1546.013 PowerShell Profileprivilege escalation, persistence30
T1552.006 Group Policy Preferencescredential access60
T1556.005 Reversible Encryptiondefense impairment, persistence, credential access00
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1564.008 Email Hiding Rulesstealth40
T1564.011 Ignore Process Interruptsstealth00
T1615 Group Policy Discoverydiscovery50
T1674 Input Injectionexecution00
T1679 Selective Exclusionstealth00
T1690 Prevent Command History Loggingdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2012-0767Adobe Flash Player T1114.002 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1007 T1082 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2020-1472Microsoft Netlogon T1087.002 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1217 Mapped
CVE-2020-5902F5 BIG-IP T1070.004 Stale
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2021-40449Microsoft Windows T1016 T1082 Mapped
CVE-2021-40539Zoho ManageEngine T1070.004 T1087.002 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1070.004 T1087.002 Mapped
CVE-2021-44515Zoho Desktop Central T1069 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-41082Microsoft Exchange Server T1059.001 T1482 Mapped
CVE-2022-41328Fortinet FortiOS T1049 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1033 Mapped
CVE-2023-22952SugarCRM Multiple Products T1070.004 T1482 Stale
CVE-2023-32315Ignite Realtime Openfire T1087.002 Mapped
CVE-2023-34362Progress MOVEit Transfer T1082 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1087.002 Mapped
CVE-2023-43770Roundcube Webmail T1082 Mapped
CVE-2024-23692Rejetto HTTP File Server T1082 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1114 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped
CVE-2024-4577PHP Group PHP T1033 Mapped
CVE-2025-32756Fortinet Multiple Products T1070.004 Mapped