kevmap

TechniquesT1003 › AN0649

AN0649 Analytic 0649

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Processes opening /proc//mem or /proc//maps targeting credential-storing services like sshd or login. Behavior often includes high privilege escalation and memory inspection tools such as gcore or gdb.</p>
Detects
T1003 OS Credential Dumping
Part of
DET0234 Credential Dumping via Sensitive Memory and Registry Access Correlation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLopenDC0055 File Access
auditd:SYSCALLptraceDC0035 Process Access
auditd:SYSCALLexecveDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TargetProcessNameDefine sensitive targets (e.g., sshd, login) being memory-read.
ToolProcessNameFlag use of memory dump tools like gcore, gdb, pmap.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-0604Microsoft SharePointMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2021-44515Zoho Desktop CentralMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-48248NAKIVO Backup and ReplicationMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-21333Microsoft WindowsMapped
CVE-2025-21334Microsoft WindowsMapped
CVE-2025-21335Microsoft WindowsMapped
CVE-2025-32709Microsoft WindowsMapped
CVE-2025-32756Fortinet Multiple ProductsMapped