kevmap

Log sources › WinEventLog:Security

WinEventLog:Security

Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, Windows

54
channels
284
analytics
280
techniques
270
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
ARP cache modification attempts observed through event tracing or security baselines DC0078 Network Traffic Flow AN1091 1
Anomalous logon without MFA enforcement DC0067 Logon Session Creation AN0814 1
Device Object Creation DC0087 Active Directory Object Creation AN0104 1
EventCode=1 DC0032 Process Creation AN1331 1
EventCode=1074 DC0018 Host Status AN1538 1
EventCode=1102 DC0038 Application Log Content AN0520 AN0535 AN1472 3
EventCode=1166, 7045 DC0018 Host Status AN1035 1
EventCode=3033 DC0016 Module Load AN0629 1
EventCode=4103, 4104, 4105, 4106 DC0064 Command Execution AN0151 1
EventCode=4624 DC0067 Logon Session Creation AN1543 1
EventCode=4624, 4625, 4768, 4769 DC0088 Logon Session Metadata AN0590 1
EventCode=4624, 4648 DC0067 Logon Session Creation AN0147 AN0199 AN0216 AN0286 AN0420 AN0444 AN0484 AN0498 AN0504 AN0687 AN0719 AN0750 AN0757 AN0791 AN0792 AN0856 AN0931 AN0954 AN1000 AN1108 AN1137 AN1144 AN1283 AN1305 AN1313 AN1344 AN1361 AN1398 AN1468 AN1551 AN1620 AN2035 32
EventCode=4625 DC0002 User Account Authentication AN0147 AN0451 AN1262 AN1521 4
EventCode=4625, 4771, 4648 DC0002 User Account Authentication AN1336 1
EventCode=4648 DC0002 User Account Authentication AN1551 1
EventCode=4657 DC0050 Windows Registry Key Access
DC0063 Windows Registry Key Modification
AN0009 AN0024 AN0051 AN0113 AN0153 AN0176 AN0287 AN0311 AN0577 AN0583 AN0595 AN0609 AN0667 AN0671 AN0909 AN0973 AN0995 AN1029 AN1097 AN1186 AN1195 AN1222 AN1246 AN1303 AN1319 AN1323 AN1446 AN1495 AN1561 AN1588 AN1598 30
EventCode=4661 DC0071 Active Directory Object Access AN0152 1
EventCode=4662 DC0071 Active Directory Object Access AN0016 AN0455 AN0648 AN0770 AN1632 5
EventCode=4663, 4656, 4658 DC0059 File Metadata AN1177 1
EventCode=4663, 4670, 4656 DC0021 OS API Execution
DC0035 Process Access
DC0038 Application Log Content
DC0050 Windows Registry Key Access
DC0055 File Access
DC0059 File Metadata
DC0061 File Modification
DC0063 Windows Registry Key Modification
DC0066 Active Directory Object Modification
AN0040 AN0065 AN0105 AN0130 AN0133 AN0139 AN0162 AN0184 AN0199 AN0229 AN0243 AN0282 AN0292 AN0331 AN0342 AN0392 AN0423 AN0436 AN0469 AN0555 AN0568 AN0616 AN0628 AN0648 AN0662 AN0705 AN0712 AN0724 AN0737 AN0755 AN0787 AN0823 AN0834 AN0854 AN0895 AN0988 AN1177 AN1198 AN1212 AN1271 AN1344 AN1357 AN1393 AN1410 AN1413 AN1417 AN1528 AN1571 AN1622 AN1626 AN2030 51
EventCode=4672 DC0088 Logon Session Metadata AN0061 AN0147 AN0170 AN0444 AN0871 AN0975 AN1094 AN1137 AN1375 AN1398 AN1419 11
EventCode=4672, 4634 DC0088 Logon Session Metadata AN0405 AN0675 AN0786 AN1253 AN1443 5
EventCode=4673 DC0013 User Account Metadata AN0384 AN0827 AN0882 AN1030 AN1398 5
EventCode=4688 DC0032 Process Creation AN0045 AN0048 AN0052 AN0095 AN0119 AN0123 AN0126 AN0178 AN0199 AN0235 AN0237 AN0240 AN0251 AN0274 AN0275 AN0298 AN0311 AN0317 AN0320 AN0323 AN0345 AN0367 AN0378 AN0406 AN0430 AN0441 AN0445 AN0474 AN0488 AN0498 AN0507 AN0513 AN0550 AN0574 AN0578 AN0608 AN0614 AN0619 AN0623 AN0643 AN0677 AN0705 AN0747 AN0764 AN0774 AN0785 AN0831 AN0834 AN0871 AN0875 AN0886 AN0927 AN0949 AN0962 AN0969 AN0975 AN0983 AN0992 AN1025 AN1028 AN1034 AN1040 AN1052 AN1064 AN1070 AN1094 AN1100 AN1113 AN1153 AN1174 AN1177 AN1178 AN1193 AN1207 AN1213 AN1253 AN1314 AN1324 AN1325 AN1335 AN1351 AN1353 AN1375 AN1394 AN1397 AN1402 AN1433 AN1446 AN1452 AN1458 AN1511 AN1528 AN1535 AN1548 AN1551 AN1567 AN1589 AN1595 AN1610 AN1611 AN1612 AN1633 AN1641 AN2030 AN2038 AN2043 AN2063 106
EventCode=4697 DC0060 Service Creation AN0778 AN1185 AN1274 AN1527 AN1575 5
EventCode=4698 DC0001 Scheduled Job Creation AN0024 AN0258 AN0324 AN0943 AN1221 AN1489 AN1507 7
EventCode=4702 DC0012 Scheduled Job Modification AN1221 1
EventCode=4704 DC0010 User Account Modification AN0854 AN1259 2
EventCode=4720 DC0014 User Account Creation AN0006 AN1001 AN1077 AN1235 AN1604 5
EventCode=4720, 4738 DC0013 User Account Metadata AN0383 1
EventCode=4723, 4724, 4740 DC0010 User Account Modification AN0334 1
EventCode=4726, 4657 DC0009 User Account Deletion AN0113 1
EventCode=4728, 4729, 4732, 4733, 4756, 4757 DC0010 User Account Modification AN0865 1
EventCode=4738, 4728, 4670 DC0010 User Account Modification AN0265 1
EventCode=4739 DC0066 Active Directory Object Modification AN0543 AN1621 2
EventCode=4768 DC0084 Active Directory Credential Request AN0316 AN0671 AN1000 AN1144 4
EventCode=4768, 4769, 4770 DC0002 User Account Authentication AN0493 1
EventCode=4769 DC0002 User Account Authentication
DC0084 Active Directory Credential Request
AN0405 AN0444 AN1000 3
EventCode=4769, 1200, 1202 DC0002 User Account Authentication AN0418 1
EventCode=4776, 4625 DC0002 User Account Authentication AN1004 AN1275 AN1476 AN1543 4
EventCode=4776, 4771, 4770 DC0088 Logon Session Metadata AN1344 1
EventCode=4778, EventCode=4779 DC0088 Logon Session Metadata AN0931 1
EventCode=4798, 4799 DC0099 Group Enumeration AN1612 1
EventCode=4800, 4801 DC0088 Logon Session Metadata AN1182 1
EventCode=4928 DC0087 Active Directory Object Creation AN0770 1
EventCode=4929 DC0068 Active Directory Object Deletion
DC0084 Active Directory Credential Request
AN0770 AN1632 2
EventCode=5136 DC0066 Active Directory Object Modification AN0383 AN0755 AN0786 AN0814 AN0854 AN1253 AN1259 7
EventCode=5140 DC0102 Network Share Access AN0516 1
EventCode=5145 DC0102 Network Share Access AN1034 AN1075 AN1145 AN1160 AN1298 AN1309 AN1516 7
EventCode=5156, 5157 DC0082 Network Connection Creation AN0633 AN1015 AN1148 AN2043 4
EventCode=6416 DC0038 Application Log Content AN0185 1
Firewall Rule Modification DC0051 Firewall Rule Modification AN0133 1
Registry key modification HKLM\Software\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast DC0063 Windows Registry Key Modification AN1274 1
modification to Winlogon registry keys such as Shell, Notify, or Userinit DC0063 Windows Registry Key Modification AN1133 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1003 OS Credential Dumpingcredential access3718
T1003.001 LSASS Memorycredential access794
T1003.002 Security Account Managercredential access280
T1003.003 NTDScredential access243
T1003.004 LSA Secretscredential access120
T1003.005 Cached Domain Credentialscredential access80
T1003.006 DCSynccredential access70
T1005 Data from Local Systemcollection1446
T1006 Direct Volume Accessstealth10
T1007 System Service Discoverydiscovery111
T1016.001 Internet Connection Discoverydiscovery00
T1020 Automated Exfiltrationexfiltration100
T1021 Remote Serviceslateral movement114
T1021.001 Remote Desktop Protocollateral movement162
T1021.002 SMB/Windows Admin Shareslateral movement380
T1021.003 Distributed Component Object Modellateral movement130
T1021.005 VNClateral movement10
T1021.006 Windows Remote Managementlateral movement110
T1025 Data from Removable Mediacollection00
T1027 Obfuscated Files or Informationstealth945
T1027.001 Binary Paddingstealth30
T1027.003 Steganographystealth50
T1027.010 Command Obfuscationstealth100
T1027.011 Fileless Storagestealth10
T1027.013 Encrypted/Encoded Filestealth00
T1027.018 Invisible Unicodestealth00
T1036.004 Masquerade Task or Servicestealth30
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1036.010 Masquerade Account Namestealth00
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1037.001 Logon Script (Windows)persistence, privilege escalation30
T1037.003 Network Logon Scriptpersistence, privilege escalation00
T1039 Data from Network Shared Drivecollection20
T1040 Network Sniffingcredential access, discovery92
T1041 Exfiltration Over C2 Channelexfiltration512
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.002 Atexecution, persistence, privilege escalation80
T1053.005 Scheduled Taskexecution, persistence, privilege escalation512
T1055.011 Extra Window Memory Injectionstealth, privilege escalation10
T1056 Input Capturecollection, credential access23
T1056.001 Keyloggingcollection, credential access31
T1057 Process Discoverydiscovery80
T1059.003 Windows Command Shellexecution466
T1068 Exploitation for Privilege Escalationprivilege escalation3169
T1069 Permission Groups Discoverydiscovery31
T1069.001 Local Groupsdiscovery160
T1069.002 Domain Groupsdiscovery150
T1070 Indicator Removalstealth203
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1070.005 Network Share Connection Removalstealth40
T1070.006 Timestompstealth60
T1070.007 Clear Network Connection History and Configurationsstealth00
T1070.008 Clear Mailbox Datastealth20
T1070.009 Clear Persistencestealth00
T1072 Software Deployment Toolsexecution, lateral movement40
T1074 Data Stagedcollection20
T1074.001 Local Data Stagingcollection40
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1078.001 Default Accountsstealth, persistence, privilege escalation, initial access40
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1078.003 Local Accountsstealth, persistence, privilege escalation, initial access51
T1080 Taint Shared Contentlateral movement00
T1082 System Information Discoverydiscovery337
T1083 File and Directory Discoverydiscovery245
T1087 Account Discoverydiscovery166
T1098 Account Manipulationpersistence, privilege escalation342
T1098.002 Additional Email Delegate Permissionspersistence, privilege escalation00
T1098.005 Device Registrationpersistence, privilege escalation10
T1098.007 Additional Local or Domain Groupspersistence, privilege escalation00
T1110 Brute Forcecredential access252
T1110.001 Password Guessingcredential access30
T1110.002 Password Crackingcredential access10
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1111 Multi-Factor Authentication Interceptioncredential access00
T1114 Email Collectioncollection43
T1114.001 Local Email Collectioncollection10
T1114.003 Email Forwarding Rulecollection60
T1120 Peripheral Device Discoverydiscovery20
T1123 Audio Capturecollection60
T1124 System Time Discoverydiscovery30
T1125 Video Capturecollection10
T1127 Trusted Developer Utilities Proxy Executionstealth, execution200
T1127.001 MSBuildstealth, execution10
T1127.002 ClickOncestealth, execution00
T1127.003 JamPlusstealth, execution00
T1129 Shared Modulesexecution20
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1133 External Remote Servicespersistence, initial access2025
T1134 Access Token Manipulationstealth, privilege escalation40
T1134.001 Token Impersonation/Theftstealth, privilege escalation91
T1134.002 Create Process with Tokenstealth, privilege escalation70
T1134.003 Make and Impersonate Tokenstealth, privilege escalation40
T1134.004 Parent PID Spoofingstealth, privilege escalation10
T1134.005 SID-History Injectionstealth, privilege escalation10
T1135 Network Share Discoverydiscovery70
T1136 Create Accountpersistence310
T1136.001 Local Accountpersistence182
T1136.002 Domain Accountpersistence60
T1176 Software Extensionspersistence10
T1176.001 Browser Extensionspersistence20
T1176.002 IDE Extensionspersistence00
T1185 Browser Session Hijackingcollection23
T1187 Forced Authenticationcredential access90
T1189 Drive-by Compromiseinitial access321
T1195.003 Compromise Hardware Supply Chaininitial access00
T1197 BITS Jobsstealth, persistence, execution160
T1199 Trusted Relationshipinitial access21
T1200 Hardware Additionsinitial access30
T1201 Password Policy Discoverydiscovery60
T1204 User Executionexecution102
T1204.001 Malicious Linkexecution411
T1204.004 Malicious Copy and Pasteexecution60
T1207 Rogue Domain Controllerdefense impairment20
T1211 Exploitation for Stealthstealth41
T1212 Exploitation for Credential Accesscredential access54
T1213 Data from Information Repositoriescollection72
T1213.006 Databasescollection00
T1218.005 Mshtastealth80
T1218.007 Msiexecstealth100
T1218.008 Odbcconfstealth80
T1218.009 Regsvcs/Regasmstealth40
T1218.010 Regsvr32stealth190
T1218.013 Mavinjectstealth20
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.001 Windows Permissionsdefense impairment50
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1482 Domain Trust Discoverydiscovery172
T1484 Domain or Tenant Policy Modificationdefense impairment, privilege escalation10
T1484.001 Group Policy Modificationdefense impairment, privilege escalation61
T1484.002 Trust Modificationdefense impairment, privilege escalation20
T1489 Service Stopimpact201
T1491 Defacementimpact00
T1491.001 Internal Defacementimpact40
T1491.002 External Defacementimpact01
T1495 Firmware Corruptionimpact12
T1496.001 Compute Hijackingimpact00
T1497.002 User Activity Based Checksstealth, discovery00
T1498.001 Direct Network Floodimpact01
T1505 Server Software Componentpersistence12
T1505.003 Web Shellpersistence3526
T1505.004 IIS Componentspersistence50
T1505.005 Terminal Services DLLpersistence10
T1518 Software Discoverydiscovery40
T1518.001 Security Software Discoverydiscovery90
T1518.002 Backup Software Discoverydiscovery00
T1529 System Shutdown/Rebootimpact80
T1531 Account Access Removalimpact91
T1534 Internal Spearphishinglateral movement00
T1539 Steal Web Session Cookiecredential access20
T1542 Pre-OS Bootstealth, persistence00
T1542.001 System Firmwarestealth, persistence20
T1543 Create or Modify System Processpersistence, privilege escalation99
T1543.003 Windows Servicepersistence, privilege escalation470
T1546 Event Triggered Executionprivilege escalation, persistence100
T1546.001 Change Default File Associationprivilege escalation, persistence50
T1546.002 Screensaverprivilege escalation, persistence40
T1546.007 Netsh Helper DLLprivilege escalation, persistence40
T1546.009 AppCert DLLsprivilege escalation, persistence20
T1546.011 Application Shimmingprivilege escalation, persistence60
T1546.012 Image File Execution Options Injectionprivilege escalation, persistence20
T1546.015 Component Object Model Hijackingprivilege escalation, persistence90
T1547 Boot or Logon Autostart Executionpersistence, privilege escalation71
T1547.002 Authentication Packagepersistence, privilege escalation10
T1547.004 Winlogon Helper DLLpersistence, privilege escalation40
T1547.005 Security Support Providerpersistence, privilege escalation10
T1547.008 LSASS Driverpersistence, privilege escalation10
T1547.014 Active Setuppersistence, privilege escalation10
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1548.002 Bypass User Account Controlprivilege escalation561
T1550 Use Alternate Authentication Materiallateral movement50
T1550.002 Pass the Hashlateral movement64
T1550.003 Pass the Ticketlateral movement70
T1552 Unsecured Credentialscredential access134
T1552.001 Credentials In Filescredential access243
T1552.004 Private Keyscredential access71
T1552.006 Group Policy Preferencescredential access60
T1553 Subvert Trust Controlsdefense impairment40
T1553.002 Code Signingdefense impairment10
T1553.003 SIP and Trust Provider Hijackingdefense impairment20
T1553.004 Install Root Certificatedefense impairment100
T1553.005 Mark-of-the-Web Bypassdefense impairment62
T1553.006 Code Signing Policy Modificationdefense impairment00
T1554 Compromise Host Software Binarypersistence60
T1555 Credentials from Password Storescredential access89
T1555.003 Credentials from Web Browserscredential access80
T1555.004 Windows Credential Managercredential access40
T1555.005 Password Managerscredential access10
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.001 Domain Controller Authenticationdefense impairment, persistence, credential access00
T1556.002 Password Filter DLLdefense impairment, persistence, credential access30
T1556.005 Reversible Encryptiondefense impairment, persistence, credential access00
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1556.008 Network Provider DLLdefense impairment, persistence, credential access00
T1557 Adversary-in-the-Middlecredential access, collection104
T1557.001 Name Resolution Poisoning and SMB Relaycredential access, collection101
T1557.002 ARP Cache Poisoningcredential access, collection00
T1558 Steal or Forge Kerberos Ticketscredential access63
T1558.001 Golden Ticketcredential access10
T1558.002 Silver Ticketcredential access10
T1558.003 Kerberoastingcredential access180
T1558.004 AS-REP Roastingcredential access00
T1559 Inter-Process Communicationexecution10
T1559.001 Component Object Modelexecution40
T1559.002 Dynamic Data Exchangeexecution10
T1560 Archive Collected Datacollection40
T1560.001 Archive via Utilitycollection172
T1560.002 Archive via Librarycollection00
T1560.003 Archive via Custom Methodcollection00
T1561 Disk Wipeimpact00
T1561.001 Disk Content Wipeimpact10
T1561.002 Disk Structure Wipeimpact10
T1563 Remote Service Session Hijackinglateral movement00
T1563.002 RDP Hijackinglateral movement20
T1564.002 Hidden Usersstealth40
T1564.005 Hidden File Systemstealth00
T1564.006 Run Virtual Instancestealth20
T1564.010 Process Argument Spoofingstealth00
T1564.012 File/Path Exclusionsstealth00
T1565 Data Manipulationimpact32
T1565.001 Stored Data Manipulationimpact62
T1565.003 Runtime Data Manipulationimpact00
T1566.002 Spearphishing Linkinitial access45
T1566.003 Spearphishing via Serviceinitial access00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1568.001 Fast Flux DNScommand and control00
T1568.002 Domain Generation Algorithmscommand and control20
T1569 System Servicesexecution40
T1569.002 Service Executionexecution431
T1570 Lateral Tool Transferlateral movement61
T1571 Non-Standard Portcommand and control51
T1574 Hijack Execution Flowstealth, execution816
T1574.001 DLLstealth, execution930
T1574.007 Path Interception by PATH Environment Variablestealth, execution20
T1574.009 Path Interception by Unquoted Pathstealth, execution00
T1574.011 Services Registry Permissions Weaknessstealth, execution110
T1574.012 COR_PROFILERstealth, execution20
T1574.014 AppDomainManagerstealth, execution00
T1606 Forge Web Credentialscredential access10
T1606.001 Web Cookiescredential access00
T1606.002 SAML Tokenscredential access00
T1611 Escape to Hostprivilege escalation23
T1614 System Location Discoverydiscovery00
T1614.001 System Language Discoverydiscovery20
T1615 Group Policy Discoverydiscovery50
T1621 Multi-Factor Authentication Request Generationcredential access20
T1649 Steal or Forge Authentication Certificatescredential access110
T1652 Device Driver Discoverydiscovery00
T1653 Power Settingspersistence11
T1654 Log Enumerationdiscovery00
T1657 Financial Theftimpact00
T1659 Content Injectioninitial access, command and control00
T1665 Hide Infrastructurecommand and control00
T1668 Exclusive Controlpersistence00
T1669 Wi-Fi Networksinitial access00
T1673 Virtual Machine Discoverydiscovery00
T1674 Input Injectionexecution00
T1679 Selective Exclusionstealth00
T1684 Social Engineeringstealth00
T1684.001 Impersonationstealth00
T1685.001 Disable or Modify Windows Event Logdefense impairment280
T1685.005 Clear Windows Event Logsdefense impairment80
T1686 Disable or Modify System Firewalldefense impairment70
T1686.003 Windows Host Firewalldefense impairment200
T1687 Exploitation for Defense Impairmentdefense impairment00
T1688 Safe Mode Bootdefense impairment00
T1689 Downgrade Attackdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 Mapped
CVE-2012-0767Adobe Flash Player T1098 T1185 T1204.001 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0629Adobe ColdFusion T1005 Mapped
CVE-2013-0641Adobe Reader T1048 Mapped
CVE-2014-0546Adobe Reader and Acrobat T1068 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-5119Adobe Flash Player T1204.001 T1566.002 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1010Adobe Flash Player and AIR T1574 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-11292Adobe Flash Player T1005 Mapped
CVE-2017-12637SAP NetWeaver T1083 T1555 Mapped
CVE-2017-5638Apache Struts T1005 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 T1574 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 Mapped
CVE-2018-15961Adobe ColdFusion T1491.002 Mapped
CVE-2018-4878Adobe Flash Player T1041 Mapped
CVE-2018-4939Adobe ColdFusion T1133 Mapped
CVE-2019-0211Apache HTTP Server T1068 Mapped
CVE-2019-0604Microsoft SharePoint T1003 T1041 T1505.003 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1133 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1083 T1133 T1552.001 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1003 T1005 T1078 Mapped
CVE-2019-13608Citrix StoreFront Server T1003 T1005 T1078 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 T1007 T1082 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 T1505.003 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1083 T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1133 Mapped
CVE-2019-5591Fortinet FortiOS T1005 T1133 T1557 Mapped
CVE-2020-0069MediaTek Multiple Chipsets T1068 Mapped
CVE-2020-0688Microsoft Exchange Server T1110 T1114 T1505.003 Mapped
CVE-2020-0787Microsoft Windows T1068 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1068 T1110 T1133 Mapped
CVE-2020-25506D-Link DNS-320 Device T1133 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1204.001 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1574 Mapped
CVE-2020-5902F5 BIG-IP T1003 T1005 T1070.004 T1133 T1552 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1556 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1133 Mapped
CVE-2021-1497Cisco HyperFlex HX T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1133 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1078 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1003 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1059.003 T1078 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1068 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1133 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 T1133 T1505.003 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 T1505.003 Mapped
CVE-2021-26858Microsoft Exchange Server T1505.003 Mapped
CVE-2021-27065Microsoft Exchange Server T1505.003 Mapped
CVE-2021-27101Accellion FTA T1005 Mapped
CVE-2021-27102Accellion FTA T1005 Mapped
CVE-2021-27103Accellion FTA T1005 Mapped
CVE-2021-27104Accellion FTA T1005 Mapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software T1505.003 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 T1068 Mapped
CVE-2021-31207Microsoft Exchange Server T1548.002 T1565 Mapped
CVE-2021-32030ASUS Routers T1040 T1068 T1098 Mapped
CVE-2021-33739Microsoft Windows T1068 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 T1053.005 T1136 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1569.002 Mapped
CVE-2021-36934Microsoft Windows T1068 T1078 Mapped
CVE-2021-4034Red Hat Polkit T1068 Mapped
CVE-2021-40449Microsoft Windows T1027 T1059.003 T1068 T1082 Mapped
CVE-2021-40539Zoho ManageEngine T1003 T1003.003 T1027 T1070.004 T1136 T1505.003 T1560.001 Mapped
CVE-2021-41379Microsoft Windows T1068 T1078 Mapped
CVE-2021-42321Microsoft Exchange T1078 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1003 T1003.003 T1027 T1070.004 T1136 T1505.003 T1560.001 Mapped
CVE-2021-44168Fortinet FortiOS T1078.003 Mapped
CVE-2021-44228Apache Log4j2 T1505.003 Mapped
CVE-2021-44515Zoho Desktop Central T1003 T1069 T1087 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 T1543 Mapped
CVE-2022-1040Sophos Firewall T1040 T1078 T1557 T1574 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1133 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1068 Mapped
CVE-2022-21919Microsoft Windows T1068 T1078 Mapped
CVE-2022-21971Microsoft Windows T1204.001 Mapped
CVE-2022-21999Microsoft Windows T1068 T1078 T1136.001 T1211 Mapped
CVE-2022-22047Microsoft Windows T1068 T1078 Mapped
CVE-2022-22718Microsoft Windows T1068 T1078 Mapped
CVE-2022-22948VMware vCenter Server T1068 T1078 T1212 Mapped
CVE-2022-22954VMware Workspace ONE Access and Identity Manager T1505.003 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1505.003 Mapped
CVE-2022-23131Zabbix Frontend T1078 T1548 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 T1213 Mapped
CVE-2022-24521Microsoft Windows T1068 T1078 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1185 T1204.001 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26500Veeam Backup & Replication T1048 T1078 Mapped
CVE-2022-26501Veeam Backup & Replication T1048 Mapped
CVE-2022-26904Microsoft Windows T1068 T1078 Mapped
CVE-2022-29303SolarView Compact T1505 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 T1574 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-37969Microsoft Windows T1068 T1078 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1068 Mapped
CVE-2022-41073Microsoft Windows T1068 T1078 T1574 Mapped
CVE-2022-41082Microsoft Exchange Server T1078 T1087 T1482 T1505.003 T1567 Mapped
CVE-2022-41125Microsoft Windows T1068 T1078 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2022-41328Fortinet FortiOS T1037 T1565.001 T1574 Mapped
CVE-2022-42475Fortinet FortiOS T1574 Mapped
CVE-2022-47966Zoho ManageEngine T1068 T1136.001 Mapped
CVE-2023-0386Linux Kernel T1543 Stale
CVE-2023-1389TP-Link Archer AX21 T1041 T1070 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1078 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1068 T1078 T1505.003 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1136 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 T1133 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1068 T1078 Mapped
CVE-2023-20867VMware Tools T1078 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-21674Microsoft Windows T1068 T1078 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1078 T1136 Mapped
CVE-2023-22952SugarCRM Multiple Products T1021.001 T1070.004 T1078 T1083 T1482 T1505.003 Stale
CVE-2023-23397Microsoft Office T1078 T1550.002 Mapped
CVE-2023-2533PaperCut NG/MF T1547 T1566.002 Mapped
CVE-2023-26360Adobe ColdFusion T1003.001 T1036.005 T1484.001 T1505.003 Mapped
CVE-2023-27524Apache Superset T1078 Mapped
CVE-2023-27532Veeam Backup & Replication T1059.003 T1087 T1133 T1555 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1136 T1574 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1068 T1078 Mapped
CVE-2023-28252Microsoft Windows T1003 T1021 T1068 T1078 T1136 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 Mapped
CVE-2023-32315Ignite Realtime Openfire T1505.003 Mapped
CVE-2023-33538TP-Link Multiple Routers T1068 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1185 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 T1082 T1136 T1531 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1136 T1213 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-36884Microsoft Windows T1005 T1489 T1553.005 Stale
CVE-2023-38035Ivanti Sentry T1557.001 T1571 Mapped
CVE-2023-38831RARLAB WinRAR T1005 T1041 T1053 T1204 Mapped
CVE-2023-38950ZKTeco BioTime T1005 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1078 T1133 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1078 Mapped
CVE-2023-42793JetBrains TeamCity T1059.003 Mapped
CVE-2023-43770Roundcube Webmail T1082 T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1068 T1543 T1548 Mapped
CVE-2023-46604Apache ActiveMQ T1053.005 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 T1505.003 T1555 Mapped
CVE-2023-48365Qlik Sense T1133 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 T1552 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 T1134.001 T1574 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 T1574 Mapped
CVE-2023-5631Roundcube Webmail T1041 T1204.001 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 T1574 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1068 Mapped
CVE-2024-12987DrayTek Vigor Routers T1068 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 T1550.002 T1558 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 T1550.002 T1558 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 T1550.002 T1558 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1653 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1078 Mapped
CVE-2024-20399Cisco NX-OS T1078 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21413Microsoft Office Outlook T1566.002 Mapped
CVE-2024-21762Fortinet FortiOS T1574 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1505.003 T1552 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 T1505.003 T1555 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 T1082 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1003.003 T1005 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1114 T1566.002 Mapped
CVE-2024-29059Microsoft .NET Framework T1068 Mapped
CVE-2024-30051Microsoft DWM Core Library T1068 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 Mapped
CVE-2024-37085VMware ESXi T1068 T1078 Mapped
CVE-2024-38080Microsoft Windows T1068 Mapped
CVE-2024-38112Microsoft Windows T1189 T1204.001 Mapped
CVE-2024-38475Apache HTTP Server T1005 Mapped
CVE-2024-41710Mitel SIP Phones T1068 Mapped
CVE-2024-41713Mitel MiCollab T1005 T1068 Mapped
CVE-2024-42009Roundcube Webmail T1056 T1114 T1566.002 Mapped
CVE-2024-45195Apache OFBiz T1133 T1498.001 Mapped
CVE-2024-4577PHP Group PHP T1003 T1003.001 T1041 T1053 T1068 T1543 T1570 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1003 T1005 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 Mapped
CVE-2024-4885Progress WhatsUp Gold T1068 Mapped
CVE-2024-49035Microsoft Partner Center T1068 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 Mapped
CVE-2024-50302Linux Kernel T1005 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2024-53104Linux Kernel T1068 Mapped
CVE-2024-53150Linux Kernel T1005 Mapped
CVE-2024-53197Linux Kernel T1068 Mapped
CVE-2024-53704SonicWall SonicOS T1021.001 T1083 T1199 T1212 Mapped
CVE-2024-54085AMI MegaRAC SPx T1068 T1495 Mapped
CVE-2024-55550Mitel MiCollab T1005 T1041 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 T1068 T1078 T1555 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1003 T1552.001 T1552.004 Mapped
CVE-2024-57968Advantive VeraCore T1078 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1565.001 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 T1068 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1003 Mapped
CVE-2025-04117-Zip 7-Zip T1553.005 Mapped
CVE-2025-0994Trimble Cityworks T1068 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1068 Mapped
CVE-2025-21333Microsoft Windows T1003 T1068 Mapped
CVE-2025-21334Microsoft Windows T1003 T1068 Mapped
CVE-2025-21335Microsoft Windows T1003 T1068 Mapped
CVE-2025-21391Microsoft Windows T1068 Mapped
CVE-2025-21418Microsoft Windows T1005 T1068 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1495 Mapped
CVE-2025-21590Juniper Junos OS T1068 Mapped
CVE-2025-22224VMware ESXi and Workstation T1611 Mapped
CVE-2025-22225VMware ESXi T1068 T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 T1611 Mapped
CVE-2025-24016Wazuh Wazuh Server T1078 Mapped
CVE-2025-24054Microsoft Windows T1555 Mapped
CVE-2025-24085Apple Multiple Products T1068 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24991Microsoft Windows T1005 Mapped
CVE-2025-24993Microsoft Windows T1068 T1204 T1565 Mapped
CVE-2025-25181Advantive VeraCore T1068 Mapped
CVE-2025-25257Fortinet FortiWeb T1068 Mapped
CVE-2025-27363FreeType FreeType T1574 Mapped
CVE-2025-2783Google Chromium Mojo T1548 Mapped
CVE-2025-30400Microsoft Windows T1068 Mapped
CVE-2025-31161CrushFTP CrushFTP T1078 T1136 Mapped
CVE-2025-31200Apple Multiple Products T1557 Stale
CVE-2025-31201Apple Multiple Products T1557 Stale
CVE-2025-31324SAP NetWeaver T1505.003 Mapped
CVE-2025-32701Microsoft Windows T1003.001 T1068 T1543 Mapped
CVE-2025-32706Microsoft Windows T1003.001 T1068 T1543 Mapped
CVE-2025-32709Microsoft Windows T1003 T1068 T1543 Mapped
CVE-2025-32756Fortinet Multiple Products T1003 T1041 T1070.004 T1133 Mapped
CVE-2025-33053Microsoft Windows T1041 T1056.001 T1543 Mapped
CVE-2025-35939Craft CMS Craft CMS T1505.003 Mapped
CVE-2025-3928Commvault Web Server T1505.003 Mapped
CVE-2025-42999SAP NetWeaver T1505.003 Mapped
CVE-2025-43200Apple Multiple Products T1005 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1505.003 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1543 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1068 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1068 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-49704Microsoft SharePoint T1059.003 Mapped
CVE-2025-49706Microsoft SharePoint T1059.003 T1505 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 T1068 T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1555 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped