{"_built":"2026-08-24 19:45 UTC","log_sources":[{"slug":"auditd-syscall","name":"auditd:SYSCALL","channels":[{"channel":"ACCESS","analytics":["AN1420"],"data_components":["DC0035"]},{"channel":"AUDIT_SYSCALL (open, write, rename, unlink)","analytics":["AN0059"],"data_components":["DC0061"]},{"channel":"Access or modification to /lib/modules or creation of .ko files","analytics":["AN1243"],"data_components":["DC0039"]},{"channel":"Access to /var/lib/sss/secrets/secrets.ldb or .secrets.mkey","analytics":["AN1444"],"data_components":["DC0055"]},{"channel":"Command line arguments including SPApplicationsDataType","analytics":["AN1102"],"data_components":["DC0064"]},{"channel":"EXECVE","analytics":["AN0312"],"data_components":["DC0032"]},{"channel":"Execution of binaries located in /etc/init.d/ or systemd service paths","analytics":["AN0765"],"data_components":["DC0032"]},{"channel":"Execution of dpkg or rpm followed by fork/execve from within postinst, prerm, etc.","analytics":["AN0939"],"data_components":["DC0032"]},{"channel":"Execution of dpkg, rpm, or other package manager with list flag","analytics":["AN1101"],"data_components":["DC0032"]},{"channel":"Execution of insmod, modprobe, or rmmod commands by non-standard users or outside expected timeframes","analytics":["AN1243"],"data_components":["DC0064"]},{"channel":"Execution of network stress tools or anomalies in socket/syscall behavior","analytics":["AN1435"],"data_components":["DC0032"]},{"channel":"Execution of script interpreters by systemd timer (ExecStart)","analytics":["AN0025"],"data_components":["DC0064"]},{"channel":"Execution of spoofing tools (e.g., hping3, nping, scapy) sending UDP packets to known amplifier ports","analytics":["AN1141"],"data_components":["DC0064"]},{"channel":"Execution of xev, xdotool, or input activity emulators","analytics":["AN1183"],"data_components":["DC0064"]},{"channel":"File creation events in /var/mail or /var/spool/mail exceeding baseline thresholds","analytics":["AN1009"],"data_components":["DC0039"]},{"channel":"File creations of *.qcow2, *.vdi, *.vmdk outside standard VM directories","analytics":["AN0910"],"data_components":["DC0039"]},{"channel":"High frequency of accept(), read(), or SSL_read() syscalls tied to nginx/apache processes","analytics":["AN0490"],"data_components":["DC0035"]},{"channel":"Inotify watch creation or auditctl changes on /etc/cron* or /lib/systemd/system/","analytics":["AN0025"],"data_components":["DC0059"]},{"channel":"Invocation of packet generation tools (e.g., hping3, nping) or fork bombs","analytics":["AN1013"],"data_components":["DC0032"]},{"channel":"Kernel Device Events - USB Block Devices","analytics":["AN0617"],"data_components":["DC0042"]},{"channel":"LD_PRELOAD Logging","analytics":["AN0390"],"data_components":["DC0016"]},{"channel":"Modification of user shell profile or trap registration via echo/redirection (e.g., echo \"trap 'malicious_cmd' INT\" >> ~/.bashrc)","analytics":["AN1038"],"data_components":["DC0061"]},{"channel":"None","analytics":["AN0213","AN1532"],"data_components":["DC0064"]},{"channel":"PATH","analytics":["AN0134","AN0279","AN0393","AN0467","AN1217","AN1438","AN1613"],"data_components":["DC0040","DC0055","DC0059","DC0061"]},{"channel":"PATH records referencing /dev/video*","analytics":["AN0569"],"data_components":["DC0055"]},{"channel":"Process segfault or abnormal termination after invoking vulnerable syscall sequence","analytics":["AN0851"],"data_components":["DC0033"]},{"channel":"Processes reading credential or token cache files","analytics":["AN0720"],"data_components":["DC0055"]},{"channel":"Reads of ~/.bash_history, ~/.mozilla, or access to /dev/input","analytics":["AN1183"],"data_components":["DC0055"]},{"channel":"Removable media mount notification","analytics":["AN0248"],"data_components":["DC0042"]},{"channel":"Rules capturing clock_gettime, time, gettimeofday syscalls when enabled","analytics":["AN0431"],"data_components":["DC0021"]},{"channel":"SYSCALL for usermod or /etc/group file modification","analytics":["AN0866"],"data_components":["DC0010"]},{"channel":"SYSCALL ptrace/mprotect","analytics":["AN0914"],"data_components":["DC0020"]},{"channel":"SYSCALL record where exe contains passwd/userdel/chage and auid != root","analytics":["AN0335"],"data_components":["DC0032"]},{"channel":"Unusual processes accessing or modifying cookie databases","analytics":["AN0485"],"data_components":["DC0055"]},{"channel":"Use of fork/exec with DISPLAY unset or redirected","analytics":["AN0361"],"data_components":["DC0034"]},{"channel":"adduser","analytics":["AN1078"],"data_components":["DC0014"]},{"channel":"apache2 or nginx spawning sh, bash, or python interpreter","analytics":["AN1109"],"data_components":["DC0032"]},{"channel":"bash/zsh of base64, tar, gzip, or openssl immediately after file write","analytics":["AN0768"],"data_components":["DC0064"]},{"channel":"capset or setns","analytics":["AN1422"],"data_components":["DC0067"]},{"channel":"chattr, rm, shred, dd run on recovery directories or partitions","analytics":["AN0934"],"data_components":["DC0064"]},{"channel":"chmod","analytics":["AN0783","AN0920"],"data_components":["DC0061"]},{"channel":"chmod, chown, setxattr, or file writes to /etc/ssl/* or /usr/local/share/ca-certificates/*","analytics":["AN1247"],"data_components":["DC0059"]},{"channel":"chmod, execve","analytics":["AN0307"],"data_components":["DC0064"]},{"channel":"chmod, write, create, open","analytics":["AN1056"],"data_components":["DC0061"]},{"channel":"chmod/chown to /etc/passwd or /etc/shadow","analytics":["AN1605"],"data_components":["DC0061"]},{"channel":"connect","analytics":["AN0145","AN0159","AN0227","AN0332","AN0368","AN0424","AN0729","AN0989","AN1390","AN1414"],"data_components":["DC0082"]},{"channel":"connect or sendto system call with burst pattern","analytics":["AN0970"],"data_components":["DC0078"]},{"channel":"connect, execve, write","analytics":["AN0166"],"data_components":["DC0064"]},{"channel":"connect/sendto","analytics":["AN0597","AN1190"],"data_components":["DC0082"]},{"channel":"creat","analytics":["AN0041","AN0765","AN0798","AN1096","AN1315"],"data_components":["DC0039"]},{"channel":"creat, open, write on /etc/systemd/system and /usr/lib/systemd/system","analytics":["AN0645"],"data_components":["DC0039"]},{"channel":"device event logs","analytics":["AN0343"],"data_components":["DC0042"]},{"channel":"dmesg","analytics":["AN1420"],"data_components":["DC0016"]},{"channel":"execution of known flash tools (e.g., flashrom, fwupd)","analytics":["AN0475"],"data_components":["DC0032"]},{"channel":"execution of realmd, samba-tool, or ldapmodify with user-related arguments","analytics":["AN0007"],"data_components":["DC0064"]},{"channel":"execution of ssh, scp, or sftp using previously unseen credentials or keys","analytics":["AN0955"],"data_components":["DC0002"]},{"channel":"execution of systemctl or service with enable/start parameters","analytics":["AN0701"],"data_components":["DC0064"]},{"channel":"execution of systemctl or service with enable/start/modify","analytics":["AN1576"],"data_components":["DC0064"]},{"channel":"execution of tools like cat, grep, or awk on credential files","analytics":["AN1154"],"data_components":["DC0064"]},{"channel":"execve","analytics":["AN0003","AN0014","AN0022","AN0041","AN0049","AN0050","AN0067","AN0076","AN0096","AN0101","AN0114","AN0125","AN0134","AN0148","AN0174","AN0195","AN0205","AN0211","AN0220","AN0227","AN0230","AN0238","AN0253","AN0255","AN0259","AN0261","AN0279","AN0288","AN0293","AN0303","AN0307","AN0318","AN0332","AN0350","AN0356","AN0364","AN0368","AN0380","AN0390","AN0393","AN0412","AN0424","AN0456","AN0467","AN0508","AN0512","AN0532","AN0541","AN0565","AN0579","AN0585","AN0603","AN0624","AN0631","AN0649","AN0652","AN0658","AN0715","AN0725","AN0735","AN0738","AN0742","AN0779","AN0783","AN0798","AN0805","AN0812","AN0839","AN0863","AN0873","AN0904","AN0914","AN0920","AN0923","AN0944","AN0967","AN0970","AN0982","AN0984","AN0989","AN1026","AN1038","AN1041","AN1056","AN1058","AN1065","AN1071","AN1081","AN1114","AN1119","AN1122","AN1166","AN1170","AN1226","AN1230","AN1234","AN1250","AN1295","AN1304","AN1315","AN1354","AN1382","AN1390","AN1395","AN1408","AN1411","AN1414","AN1420","AN1429","AN1438","AN1441","AN1453","AN1463","AN1490","AN1492","AN1508","AN1529","AN1544","AN1549","AN1552","AN1600","AN1627","AN2031"],"data_components":["DC0032"]},{"channel":"execve call for modification of /etc/sudoers or writing to /var/db/sudo","analytics":["AN0142"],"data_components":["DC0061"]},{"channel":"execve call for sudo where euid != uid","analytics":["AN0142"],"data_components":["DC0034"]},{"channel":"execve call including 'nohup' or trailing '&'","analytics":["AN0181"],"data_components":["DC0064"]},{"channel":"execve call with argv matching known disk enumeration commands (lsblk, parted, fdisk)","analytics":["AN0537"],"data_components":["DC0032"]},{"channel":"execve calls for qemu-system*, kvm, or VBoxHeadless","analytics":["AN0910"],"data_components":["DC0032"]},{"channel":"execve calls modifying HISTFILE or HISTCONTROL via unset/export","analytics":["AN1555"],"data_components":["DC0064"]},{"channel":"execve calls modifying local mail filter configuration files","analytics":["AN0553"],"data_components":["DC0064"]},{"channel":"execve calls to /usr/bin/locale or shell execution of $LANG","analytics":["AN1562"],"data_components":["DC0064"]},{"channel":"execve calls to locale, timedatectl, or cat /etc/timezone","analytics":["AN0120"],"data_components":["DC0064"]},{"channel":"execve calls to soffice.bin with suspicious macro execution flags","analytics":["AN0035"],"data_components":["DC0032"]},{"channel":"execve calls with high-frequency or known bandwidth-intensive tools","analytics":["AN0081"],"data_components":["DC0032"]},{"channel":"execve for proxy tools","analytics":["AN1021"],"data_components":["DC0032"]},{"channel":"execve logging for /usr/bin/systemctl and systemd-run","analytics":["AN0645"],"data_components":["DC0032"]},{"channel":"execve network tools","analytics":["AN0031"],"data_components":["DC0032"]},{"channel":"execve of /bin/sh,/bin/bash,/usr/bin/curl,/usr/bin/python by service accounts (e.g., apache, mysql, nobody) immediately after inbound network activity.","analytics":["AN0328"],"data_components":["DC0032"]},{"channel":"execve of base64|openssl|xxd|python|perl with arguments matching Base64 flags","analytics":["AN0346"],"data_components":["DC0032"]},{"channel":"execve of curl, rsync, wget with internal knowledge base or IPs","analytics":["AN1161"],"data_components":["DC0064"]},{"channel":"execve of dd or sed targeting /proc/*/mem","analytics":["AN1494"],"data_components":["DC0021"]},{"channel":"execve of interpreters (python, perl), custom binaries, or shell utilities with long arguments containing non-standard tokens","analytics":["AN0928"],"data_components":["DC0032"]},{"channel":"execve of launchctl or pkill","analytics":["AN0063"],"data_components":["DC0032"]},{"channel":"execve of re-parented process","analytics":["AN1223"],"data_components":["DC0032"]},{"channel":"execve of sleep or ping command within script interpreted by bash/python","analytics":["AN0397"],"data_components":["DC0032"]},{"channel":"execve of smbclient, smbmap, rpcclient, nmblookup, crackmapexec smb","analytics":["AN0514"],"data_components":["DC0032"]},{"channel":"execve of system tools like dmidecode, lspci, lscpu, dmesg, systemd-detect-virt","analytics":["AN0479"],"data_components":["DC0032"]},{"channel":"execve of systemctl or service stop","analytics":["AN0062"],"data_components":["DC0032"]},{"channel":"execve on code or jetbrains-gateway with remote flags","analytics":["AN0376"],"data_components":["DC0032"]},{"channel":"execve or nanosleep with no stdout/stderr I/O","analytics":["AN1049"],"data_components":["DC0032"]},{"channel":"execve or socket/connect system calls for processes using RSA handshake","analytics":["AN1497"],"data_components":["DC0032"]},{"channel":"execve or socket/connect system calls from processes using crypto libraries","analytics":["AN0401"],"data_components":["DC0032"]},{"channel":"execve or syscall invoking vm artifact check commands (e.g., dmidecode, lspci, dmesg)","analytics":["AN0128"],"data_components":["DC0032"]},{"channel":"execve syscalls for discovery commands (uname, hostname, id, whoami, ps, netstat, mount) with command-line parameter analysis","analytics":["AN1306"],"data_components":["DC0064"]},{"channel":"execve with LD_PRELOAD or linker-related environment variables set","analytics":["AN1209"],"data_components":["DC0032"]},{"channel":"execve with UID ≠ EUID","analytics":["AN0976"],"data_components":["DC0034"]},{"channel":"execve with escalated privileges","analytics":["AN0977"],"data_components":["DC0034"]},{"channel":"execve, USER_CMD","analytics":["AN0751"],"data_components":["DC0064"]},{"channel":"execve, connect","analytics":["AN0638"],"data_components":["DC0032"]},{"channel":"execve, fork, mmap, ptrace","analytics":["AN1466"],"data_components":["DC0035"]},{"channel":"execve, prctl, or ptrace activity affecting process memory or command-line arguments","analytics":["AN0466"],"data_components":["DC0034"]},{"channel":"execve, setifflags","analytics":["AN0876"],"data_components":["DC0032"]},{"channel":"execve, unlink","analytics":["AN1481"],"data_components":["DC0032"]},{"channel":"execve,socket,connect,openat","analytics":["AN1345"],"data_components":["DC0088"]},{"channel":"execve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shells","analytics":["AN1367"],"data_components":["DC0032"]},{"channel":"execve: Commands altering firewall or enabling listeners (iptables, nft, ufw, firewall-cmd, systemctl start *ssh*/*telnet*, ip route add, tcpdump, tshark)","analytics":["AN1449"],"data_components":["DC0032"]},{"channel":"execve: Commands executed within an SSH session where no matching logon/authentication event exists","analytics":["AN0217"],"data_components":["DC0064"]},{"channel":"execve: Commands like systemctl stop <service>, service <service> stop, or kill -9 <pid>","analytics":["AN0046"],"data_components":["DC0064"]},{"channel":"execve: Commands that alter firewall or start listeners: iptables|nft|ufw|firewall-cmd|pfctl|systemctl start sshd/telnet/dropbear; raw-socket/libpcap tools (tcpdump, tshark, nmap --raw).","analytics":["AN0843"],"data_components":["DC0032"]},{"channel":"execve: Electron-based binary spawning shell or script interpreter","analytics":["AN0072"],"data_components":["DC0032"]},{"channel":"execve: Execs of chromium, google-chrome, firefox, libreoffice with http(s) in cmdline","analytics":["AN0179"],"data_components":["DC0082"]},{"channel":"execve: Execution of CLI tools like psql, mysql, mongo, sqlite3","analytics":["AN0676"],"data_components":["DC0032"]},{"channel":"execve: Execution of bash, python, or perl processes spawned by browser/email client","analytics":["AN0321"],"data_components":["DC0032"]},{"channel":"execve: Execution of binaries/scripts presenting false health messages for security daemons","analytics":["AN0869"],"data_components":["DC0032"]},{"channel":"execve: Execution of cat, less, grep, journalctl targeting log directories (/var/log/)","analytics":["AN0706"],"data_components":["DC0064"]},{"channel":"execve: Execution of commands modifying iptables/nftables to block selective IPs","analytics":["AN1149"],"data_components":["DC0032"]},{"channel":"execve: Execution of container management CLIs (docker, crictl, kubectl) or interpreted shells (sh, bash, python) within container context","analytics":["AN0233"],"data_components":["DC0032"]},{"channel":"execve: Execution of curl or wget writing files to /tmp/* followed by chmod or execution","analytics":["AN0993"],"data_components":["DC0064"]},{"channel":"execve: Execution of curl, wget, or custom scripts accessing financial endpoints","analytics":["AN1362"],"data_components":["DC0064"]},{"channel":"execve: Execution of discovery commands targeting backup binaries, processes, or config paths","analytics":["AN0241"],"data_components":["DC0032"]},{"channel":"execve: Execution of downgraded interpreters such as python2 or forced fallback commands","analytics":["AN0996"],"data_components":["DC0064"]},{"channel":"execve: Execution of files saved in mail or download directories","analytics":["AN0656"],"data_components":["DC0032"]},{"channel":"execve: Execution of interpreters creating archive-like outputs without calling tar/gzip","analytics":["AN1214"],"data_components":["DC0064"]},{"channel":"execve: Execution of klist, kinit, or tools interacting with ccache outside normal user context","analytics":["AN0069"],"data_components":["DC0032"]},{"channel":"execve: Execution of lsmod, modinfo, or cat /proc/modules","analytics":["AN1596"],"data_components":["DC0064"]},{"channel":"execve: Execution of pip, npm, gem, or similar package managers","analytics":["AN0698"],"data_components":["DC0032"]},{"channel":"execve: Execution of python, perl, or custom binaries invoking compression libraries","analytics":["AN0748"],"data_components":["DC0064"]},{"channel":"execve: Execution of scripts or binaries sourced from mail directories (/var/mail, ~/Maildir)","analytics":["AN0189"],"data_components":["DC0032"]},{"channel":"execve: Execution of scripts or binaries spawned from browser processes","analytics":["AN0299"],"data_components":["DC0032"]},{"channel":"execve: Execution of suspicious exploit binaries targeting security daemons","analytics":["AN1634"],"data_components":["DC0032"]},{"channel":"execve: Execution of systemctl, loginctl, or systemd-inhibit commands related to sleep/hibernate","analytics":["AN1175"],"data_components":["DC0064"]},{"channel":"execve: Execution of tar, gzip, bzip2, or openssl with output redirection","analytics":["AN1459"],"data_components":["DC0064"]},{"channel":"execve: Execution of tar, gzip, bzip2, xz, zip, or openssl with compression/encryption arguments","analytics":["AN0832"],"data_components":["DC0064"]},{"channel":"execve: Invocation of scp, rsync, curl, or sftp","analytics":["AN0517"],"data_components":["DC0064"]},{"channel":"execve: Process in container namespace executes curl|wget|bash|sh|python|nc with outbound args","analytics":["AN0691"],"data_components":["DC0064"]},{"channel":"execve: Processes executing sendmail/postfix with forged headers","analytics":["AN0793"],"data_components":["DC0064"]},{"channel":"execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login)","analytics":["AN0494"],"data_components":["DC0032"]},{"channel":"execve: exe in (/usr/bin/bash,/usr/bin/sh,/usr/bin/zsh,/usr/bin/python*) AND cmdline matches '(curl|wget).*(\\||\\|\\s*sh|bash)|base64\\s*-d|python\\s*-c'","analytics":["AN0963"],"data_components":["DC0032"]},{"channel":"execve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser","analytics":["AN0821"],"data_components":["DC0032"]},{"channel":"execve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget)","analytics":["AN0499"],"data_components":["DC0032"]},{"channel":"execve: execve where exe=/usr/bin/python3 or similar interpreter","analytics":["AN0713"],"data_components":["DC0032"]},{"channel":"execve: iptables, nft, firewall-cmd modifications","analytics":["AN0407"],"data_components":["DC0064"]},{"channel":"execve: openssl pkcs12, certutil, keytool","analytics":["AN0672"],"data_components":["DC0064"]},{"channel":"execve: parent process is usb/hid device handler, child process bash/python invoked","analytics":["AN1568"],"data_components":["DC0032"]},{"channel":"execve: process_name IN (\"virsh\", \"VBoxManage\", \"qemu-img\") AND command IN (\"list\", \"info\")","analytics":["AN0573"],"data_components":["DC0064"]},{"channel":"execve: service stop syslog, systemctl stop rsyslog, kill -9 syslog","analytics":["AN0668"],"data_components":["DC0064"]},{"channel":"execve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd)","analytics":["AN1370"],"data_components":["DC0032"]},{"channel":"execve=/sbin/shutdown or /sbin/reboot","analytics":["AN1539"],"data_components":["DC0064"]},{"channel":"exit_group","analytics":["AN0373"],"data_components":["DC0033"]},{"channel":"file","analytics":["AN1418"],"data_components":["DC0055"]},{"channel":"file creation/modification","analytics":["AN0166"],"data_components":["DC0039"]},{"channel":"file deletion","analytics":["AN0114"],"data_components":["DC0040"]},{"channel":"file write after sleep delay","analytics":["AN0397"],"data_components":["DC0059"]},{"channel":"file write operations in /Library/WebServer/Documents","analytics":["AN1110"],"data_components":["DC0061"]},{"channel":"firmware_update, kexec_load","analytics":["AN1036"],"data_components":["DC0018"]},{"channel":"fork/clone/daemon syscall tracing","analytics":["AN1223"],"data_components":["DC0021"]},{"channel":"fork/exec of service via PID 1 (systemd)","analytics":["AN0701"],"data_components":["DC0032"]},{"channel":"ioctl/write: Direct firmware update or device memory manipulation syscalls","analytics":["AN0917"],"data_components":["DC0004"]},{"channel":"ioctl: Changes to wireless network interfaces (up, down, reassociate)","analytics":["AN1477"],"data_components":["DC0078"]},{"channel":"kill syscalls targeting auditd process","analytics":["AN0171"],"data_components":["DC0020"]},{"channel":"kill syscalls targeting logging/security processes","analytics":["AN0887"],"data_components":["DC0033"]},{"channel":"mknod,open,openat","analytics":["AN0186"],"data_components":["DC0042"]},{"channel":"mmap","analytics":["AN0920"],"data_components":["DC0016"]},{"channel":"mmap, ptrace, process_vm_writev or direct memory ops","analytics":["AN0579"],"data_components":["DC0021"]},{"channel":"modification of entrypoint scripts or init containers","analytics":["AN1578"],"data_components":["DC0061"]},{"channel":"modification of existing .service file","analytics":["AN0701"],"data_components":["DC0061"]},{"channel":"module load or memory map path","analytics":["AN1466"],"data_components":["DC0016"]},{"channel":"mount or losetup commands creating hidden or encrypted FS","analytics":["AN1272"],"data_components":["DC0061"]},{"channel":"mount system call with bind or remap flags","analytics":["AN1196"],"data_components":["DC0021"]},{"channel":"mprotect","analytics":["AN0067"],"data_components":["DC0020"]},{"channel":"new file created in /var/www/html, /srv/http, or similar web root","analytics":["AN1109"],"data_components":["DC0039"]},{"channel":"open","analytics":["AN0125","AN0195","AN0332","AN0343","AN0368","AN0532","AN0620","AN0649","AN0725","AN0798","AN0984","AN1038","AN1071","AN1096","AN1310","AN1315","AN1400","AN1529","AN1552"],"data_components":["DC0055"]},{"channel":"open or connect syscalls on /tmp/ssh-* or $SSH_AUTH_SOCK","analytics":["AN0710"],"data_components":["DC0082"]},{"channel":"open or creat syscalls targeting excluded paths","analytics":["AN0140"],"data_components":["DC0039"]},{"channel":"open or read to browser cookie storage","analytics":["AN1403"],"data_components":["DC0055"]},{"channel":"open, flock, fcntl, unlink","analytics":["AN0373"],"data_components":["DC0055"]},{"channel":"open, read","analytics":["AN0244","AN0283","AN0617","AN1234","AN1414","AN1631"],"data_components":["DC0055"]},{"channel":"open, read, mount","analytics":["AN1411"],"data_components":["DC0055"]},{"channel":"open, read, or stat of browser config files","analytics":["AN0038"],"data_components":["DC0055"]},{"channel":"open, read: /etc/ssl/, /etc/pki/, ~/.pki/nssdb/","analytics":["AN0672"],"data_components":["DC0055"]},{"channel":"open, rename","analytics":["AN0541","AN1481"],"data_components":["DC0020"]},{"channel":"open, unlink, rename: File creation or deletion involving critical stored data","analytics":["AN0556"],"data_components":["DC0039"]},{"channel":"open, unlink, rename: Suspicious file access, deletion, or modification of sensitive paths","analytics":["AN0163"],"data_components":["DC0061"]},{"channel":"open, write","analytics":["AN0056","AN0288","AN0600","AN0824","AN0950","AN1065","AN1250","AN1408"],"data_components":["DC0061"]},{"channel":"open, write, unlink","analytics":["AN0974"],"data_components":["DC0039"]},{"channel":"open, write: File modifications under /etc/ssl/certs, /usr/local/share/ca-certificates, or /etc/pki/ca-trust/source/anchors","analytics":["AN0154"],"data_components":["DC0061"]},{"channel":"open, write: File writes to application binaries or libraries at runtime","analytics":["AN1098"],"data_components":["DC0061"]},{"channel":"open, write: Modification of /boot/grub/* or /boot/efi/*","analytics":["AN0775"],"data_components":["DC0061"]},{"channel":"open, write: Write operations targeting /dev/sda, /dev/nvme0n1, or EFI partition mounts","analytics":["AN0429"],"data_components":["DC0061"]},{"channel":"open,creat,rename,write","analytics":["AN1549"],"data_components":["DC0039"]},{"channel":"open,creat,rename: Writes in $HOME/Downloads, /tmp, ~/.cache with exe/script/archive/office extensions","analytics":["AN0179"],"data_components":["DC0039"]},{"channel":"open,create","analytics":["AN1382"],"data_components":["DC0039"]},{"channel":"open,openat,read","analytics":["AN0456"],"data_components":["DC0013"]},{"channel":"open,read","analytics":["AN1146"],"data_components":["DC0055"]},{"channel":"open/create/rename: name in (/home/*/Downloads/*|/tmp/*|/run/user/*|/media/*) AND ext in SuspiciousExtensions","analytics":["AN0821"],"data_components":["DC0039"]},{"channel":"open/read","analytics":["AN1199","AN1354"],"data_components":["DC0055"]},{"channel":"open/read access to ~/.bash_history","analytics":["AN1085"],"data_components":["DC0055"]},{"channel":"open/read of sensitive config or secret files","analytics":["AN0857"],"data_components":["DC0055"]},{"channel":"open/read of sensitive directories","analytics":["AN0896"],"data_components":["DC0055"]},{"channel":"open/read of sensitive directories (/etc, /home/*)","analytics":["AN1512"],"data_components":["DC0055"]},{"channel":"open/read on ~/.local/share/keepassxc/* OR ~/.password-store/*","analytics":["AN1642"],"data_components":["DC0055"]},{"channel":"open/read system calls to ~/.bash_history or /etc/shadow","analytics":["AN1154"],"data_components":["DC0055"]},{"channel":"open/read: Access to /proc/self/status with focus on TracerPID field","analytics":["AN1046"],"data_components":["DC0055"]},{"channel":"open/write calls modifying ~/.bashrc, ~/.profile, or /etc/paths.d","analytics":["AN0010"],"data_components":["DC0061"]},{"channel":"open/write of .service unit files","analytics":["AN0200"],"data_components":["DC0061"]},{"channel":"open/write syscalls on /dev/sd* or /dev/nvme*","analytics":["AN0385"],"data_components":["DC0054"]},{"channel":"open/write syscalls targeting /etc/ld.so.preload or binaries in /usr/bin","analytics":["AN0610"],"data_components":["DC0061"]},{"channel":"open/write syscalls targeting web directory files","analytics":["AN1623"],"data_components":["DC0061"]},{"channel":"open/write syscalls to block devices (/dev/sd*, /dev/nvme*)","analytics":["AN0883"],"data_components":["DC0054"]},{"channel":"open/write to /etc/pam.d/*","analytics":["AN0546"],"data_components":["DC0061"]},{"channel":"open/write to /proc/*/mem or /proc/*/maps","analytics":["AN1494"],"data_components":["DC0061"]},{"channel":"open/write/unlink","analytics":["AN0230"],"data_components":["DC0061"]},{"channel":"open: Access to named pipes or FIFO in /tmp or /dev/shm by unexpected processes","analytics":["AN1358"],"data_components":["DC0055"]},{"channel":"open: File access attempt on /tmp/krb5cc_* or /tmp/krb5.ccache","analytics":["AN0069"],"data_components":["DC0055"]},{"channel":"open: File creation under /tmp, /var/tmp, ~/.cache with executable bit or shell shebang","analytics":["AN0963"],"data_components":["DC0039"]},{"channel":"open: Write to ~/.vscode-cli/code_tunnel.json","analytics":["AN0376"],"data_components":["DC0039"]},{"channel":"openat","analytics":["AN0096","AN0783","AN1517"],"data_components":["DC0055"]},{"channel":"openat, write, rename, unlink","analytics":["AN0603"],"data_components":["DC0061"]},{"channel":"openat,connect -k discovery","analytics":["AN1552"],"data_components":["DC0082"]},{"channel":"openat/read/ioctl: openat/read/ioctl on /dev/video* by uncommon user/process","analytics":["AN0569"],"data_components":["DC0021"]},{"channel":"openat/read/mmap: Open/mmap .so files from non-standard paths","analytics":["AN0053"],"data_components":["DC0016"]},{"channel":"outbound connections","analytics":["AN1377","AN2031"],"data_components":["DC0082"]},{"channel":"pam_authenticate, sshd","analytics":["AN0591"],"data_components":["DC0002"]},{"channel":"process persists beyond parent shell termination","analytics":["AN0181"],"data_components":["DC0032"]},{"channel":"promiscuous mode transitions (ioctl or ifconfig)","analytics":["AN0876"],"data_components":["DC0064"]},{"channel":"ptrace","analytics":["AN0649","AN1642"],"data_components":["DC0035"]},{"channel":"ptrace attach","analytics":["AN0106","AN0157"],"data_components":["DC0035"]},{"channel":"ptrace or process_vm_readv","analytics":["AN1631"],"data_components":["DC0035"]},{"channel":"ptrace syscall or access to /proc/*/mem","analytics":["AN1403"],"data_components":["DC0035"]},{"channel":"ptrace, ioctl","analytics":["AN0244","AN0283"],"data_components":["DC0021"]},{"channel":"ptrace, mmap, mprotect, open, dlopen","analytics":["AN1241"],"data_components":["DC0021"]},{"channel":"ptrace, mmap, process_vm_writev","analytics":["AN1400"],"data_components":["DC0021"]},{"channel":"read of /run/secrets or docker volumes by non-entrypoint process","analytics":["AN1158"],"data_components":["DC0055"]},{"channel":"read/open of sensitive file directories","analytics":["AN0788","AN1572"],"data_components":["DC0055"]},{"channel":"read/open of sensitive files","analytics":["AN0437"],"data_components":["DC0055"]},{"channel":"rename","analytics":["AN0984"],"data_components":["DC0020"]},{"channel":"rename, chmod","analytics":["AN0022"],"data_components":["DC0020"]},{"channel":"rename,chmod","analytics":["AN0798","AN1315"],"data_components":["DC0061"]},{"channel":"send, recv, write: Abnormal interception or alteration of transmitted data","analytics":["AN0703"],"data_components":["DC0021"]},{"channel":"sendto/connect","analytics":["AN1255"],"data_components":["DC0082"]},{"channel":"setsockopt, ioctl modifying ARP entries","analytics":["AN1092"],"data_components":["DC0085"]},{"channel":"setuid or setgid bit changes","analytics":["AN0976"],"data_components":["DC0059"]},{"channel":"setxattr or getxattr system call","analytics":["AN1135"],"data_components":["DC0059"]},{"channel":"sleep function usage or loops (nanosleep, usleep) in scripts","analytics":["AN0128"],"data_components":["DC0064"]},{"channel":"socket(AF_PACKET|AF_INET, SOCK_RAW, *), setsockopt(… SO_ATTACH_FILTER|SO_ATTACH_BPF …), bpf(cmd=BPF_PROG_LOAD), open/openat path=\"/dev/bpf*\" (BSD/macOS-like) or setcap cap_net_raw.","analytics":["AN0463"],"data_components":["DC0032"]},{"channel":"socket/bind: New bind() to a previously closed port shortly after the sequence.","analytics":["AN0843"],"data_components":["DC0082"]},{"channel":"socket/bind: Process binds to a new local port shortly after knock","analytics":["AN1449"],"data_components":["DC0082"]},{"channel":"socket/connect","analytics":["AN0110","AN1179","AN1332"],"data_components":["DC0078"]},{"channel":"socket/connect calls showing SSH processes forwarding arbitrary ports","analytics":["AN1484"],"data_components":["DC0082"]},{"channel":"socket/connect syscalls","analytics":["AN0634"],"data_components":["DC0078"]},{"channel":"socket/connect with TLS context by unexpected process","analytics":["AN0760"],"data_components":["DC0082"]},{"channel":"socket: Suspicious creation of AF_UNIX sockets outside expected daemons","analytics":["AN1358"],"data_components":["DC0032"]},{"channel":"ssh logins or execve of remote commands","analytics":["AN1005"],"data_components":["DC0088"]},{"channel":"stat and lstat syscall results on files, including inode and permission info","analytics":["AN2064"],"data_components":["DC0059"]},{"channel":"sudo or pkexec invocation","analytics":["AN0976"],"data_components":["DC0021"]},{"channel":"syscall in (chmod, fchmod, fchmodat, chown, fchown, fchownat, lchown, setxattr, lsetxattr, fsetxattr, removexattr, lremovexattr, fremovexattr)","analytics":["AN0998"],"data_components":["DC0059"]},{"channel":"syscall in (chmod, fchmod, fchmodat, chown, fchown, fchownat, setxattr, lsetxattr, fsetxattr)","analytics":["AN0835"],"data_components":["DC0059"]},{"channel":"type=EXECVE or SYSCALL for /bin/date, /usr/bin/timedatectl, /sbin/hwclock, /bin/cat /etc/timezone, /bin/cat /proc/uptime","analytics":["AN0431"],"data_components":["DC0032"]},{"channel":"udev events or drive enumeration involving TinyPilot paths or device classes","analytics":["AN0447"],"data_components":["DC0042"]},{"channel":"unlink, rename, open","analytics":["AN0521"],"data_components":["DC0040"]},{"channel":"unlink, unlinkat, openat, write","analytics":["AN0412"],"data_components":["DC0040"]},{"channel":"unlink, unlinkat, rmdir","analytics":["AN0416"],"data_components":["DC0040"]},{"channel":"unlink/unlinkat","analytics":["AN0738"],"data_components":["DC0040"]},{"channel":"unlink/unlinkat on service binaries or data targets","analytics":["AN0062"],"data_components":["DC0040"]},{"channel":"unshare, mount, keyctl, setns syscalls executed by containerized processes","analytics":["AN0613"],"data_components":["DC0021"]},{"channel":"useradd or adduser executed","analytics":["AN1236","AN1605"],"data_components":["DC0014"]},{"channel":"usermod, groupmod, passwd","analytics":["AN0266"],"data_components":["DC0010"]},{"channel":"usermod, or account rename system calls","analytics":["AN1078"],"data_components":["DC0010"]},{"channel":"write","analytics":["AN0283","AN0368","AN0473","AN0620","AN0663","AN0765","AN0779","AN0783","AN0805","AN0914","AN0939","AN0944","AN1299","AN1320","AN1592","AN1631"],"data_components":["DC0039","DC0061"]},{"channel":"write access to /dev/mem or /sys/firmware/efi/efivars","analytics":["AN0475"],"data_components":["DC0004"]},{"channel":"write operation on /etc/passwd or /etc/shadow","analytics":["AN1236"],"data_components":["DC0061"]},{"channel":"write or create file after .bash_history access","analytics":["AN1085"],"data_components":["DC0039"]},{"channel":"write or rename to /etc/systemd/system or /etc/init.d","analytics":["AN1576"],"data_components":["DC0061"]},{"channel":"write syscalls to /dev/sd* targeting offset 0","analytics":["AN0828"],"data_components":["DC0054"]},{"channel":"write | PATH=/home/*/.ssh/authorized_keys","analytics":["AN0350"],"data_components":["DC0061"]},{"channel":"write, open, or rename to /etc/systemd/system/*.service","analytics":["AN0701"],"data_components":["DC0039"]},{"channel":"write, rename","analytics":["AN0259"],"data_components":["DC0061"]},{"channel":"write/open, FIM audit","analytics":["AN0248"],"data_components":["DC0039"]},{"channel":"write: Modification of structured stored data by suspicious processes","analytics":["AN0556"],"data_components":["DC0061"]}],"data_components":["DC0002","DC0004","DC0010","DC0013","DC0014","DC0016","DC0018","DC0020","DC0021","DC0032","DC0033","DC0034","DC0035","DC0039","DC0040","DC0042","DC0054","DC0055","DC0059","DC0061","DC0064","DC0067","DC0078","DC0082","DC0085","DC0088"],"analytics":["AN0003","AN0007","AN0010","AN0014","AN0022","AN0025","AN0031","AN0035","AN0038","AN0041","AN0046","AN0049","AN0050","AN0053","AN0056","AN0059","AN0062","AN0063","AN0067","AN0069","AN0072","AN0076","AN0081","AN0096","AN0101","AN0106","AN0110","AN0114","AN0120","AN0125","AN0128","AN0134","AN0140","AN0142","AN0145","AN0148","AN0154","AN0157","AN0159","AN0163","AN0166","AN0171","AN0174","AN0179","AN0181","AN0186","AN0189","AN0195","AN0200","AN0205","AN0211","AN0213","AN0217","AN0220","AN0227","AN0230","AN0233","AN0238","AN0241","AN0244","AN0248","AN0253","AN0255","AN0259","AN0261","AN0266","AN0279","AN0283","AN0288","AN0293","AN0299","AN0303","AN0307","AN0312","AN0318","AN0321","AN0328","AN0332","AN0335","AN0343","AN0346","AN0350","AN0356","AN0361","AN0364","AN0368","AN0373","AN0376","AN0380","AN0385","AN0390","AN0393","AN0397","AN0401","AN0407","AN0412","AN0416","AN0424","AN0429","AN0431","AN0437","AN0447","AN0456","AN0463","AN0466","AN0467","AN0473","AN0475","AN0479","AN0485","AN0490","AN0494","AN0499","AN0508","AN0512","AN0514","AN0517","AN0521","AN0532","AN0537","AN0541","AN0546","AN0553","AN0556","AN0565","AN0569","AN0573","AN0579","AN0585","AN0591","AN0597","AN0600","AN0603","AN0610","AN0613","AN0617","AN0620","AN0624","AN0631","AN0634","AN0638","AN0645","AN0649","AN0652","AN0656","AN0658","AN0663","AN0668","AN0672","AN0676","AN0691","AN0698","AN0701","AN0703","AN0706","AN0710","AN0713","AN0715","AN0720","AN0725","AN0729","AN0735","AN0738","AN0742","AN0748","AN0751","AN0760","AN0765","AN0768","AN0775","AN0779","AN0783","AN0788","AN0793","AN0798","AN0805","AN0812","AN0821","AN0824","AN0828","AN0832","AN0835","AN0839","AN0843","AN0851","AN0857","AN0863","AN0866","AN0869","AN0873","AN0876","AN0883","AN0887","AN0896","AN0904","AN0910","AN0914","AN0917","AN0920","AN0923","AN0928","AN0934","AN0939","AN0944","AN0950","AN0955","AN0963","AN0967","AN0970","AN0974","AN0976","AN0977","AN0982","AN0984","AN0989","AN0993","AN0996","AN0998","AN1005","AN1009","AN1013","AN1021","AN1026","AN1036","AN1038","AN1041","AN1046","AN1049","AN1056","AN1058","AN1065","AN1071","AN1078","AN1081","AN1085","AN1092","AN1096","AN1098","AN1101","AN1102","AN1109","AN1110","AN1114","AN1119","AN1122","AN1135","AN1141","AN1146","AN1149","AN1154","AN1158","AN1161","AN1166","AN1170","AN1175","AN1179","AN1183","AN1190","AN1196","AN1199","AN1209","AN1214","AN1217","AN1223","AN1226","AN1230","AN1234","AN1236","AN1241","AN1243","AN1247","AN1250","AN1255","AN1272","AN1295","AN1299","AN1304","AN1306","AN1310","AN1315","AN1320","AN1332","AN1345","AN1354","AN1358","AN1362","AN1367","AN1370","AN1377","AN1382","AN1390","AN1395","AN1400","AN1403","AN1408","AN1411","AN1414","AN1418","AN1420","AN1422","AN1429","AN1435","AN1438","AN1441","AN1444","AN1449","AN1453","AN1459","AN1463","AN1466","AN1477","AN1481","AN1484","AN1490","AN1492","AN1494","AN1497","AN1508","AN1512","AN1517","AN1529","AN1532","AN1539","AN1544","AN1549","AN1552","AN1555","AN1562","AN1568","AN1572","AN1576","AN1578","AN1592","AN1596","AN1600","AN1605","AN1613","AN1623","AN1627","AN1631","AN1634","AN1642","AN2031","AN2064"],"techniques":["T1001","T1001.001","T1001.002","T1001.003","T1003","T1003.005","T1003.007","T1003.008","T1005","T1008","T1011","T1011.001","T1020","T1021","T1025","T1027","T1027.001","T1027.002","T1027.003","T1027.004","T1027.005","T1027.006","T1027.008","T1027.009","T1027.010","T1027.011","T1027.013","T1027.014","T1027.015","T1027.016","T1027.017","T1027.018","T1029","T1030","T1033","T1036","T1036.002","T1036.003","T1036.005","T1036.006","T1036.008","T1036.009","T1036.010","T1036.011","T1036.012","T1037","T1037.004","T1039","T1040","T1041","T1046","T1048","T1048.001","T1048.002","T1048.003","T1049","T1052","T1052.001","T1053","T1053.002","T1053.003","T1053.006","T1055","T1055.008","T1055.009","T1055.014","T1056","T1056.001","T1056.002","T1056.003","T1056.004","T1057","T1059","T1059.004","T1059.005","T1059.006","T1059.007","T1059.011","T1059.013","T1068","T1069","T1069.001","T1069.002","T1070","T1070.003","T1070.004","T1070.006","T1070.007","T1070.008","T1070.009","T1070.010","T1071","T1071.001","T1071.002","T1071.003","T1071.004","T1071.005","T1072","T1074","T1074.001","T1074.002","T1078","T1078.002","T1080","T1082","T1083","T1087","T1087.002","T1090","T1090.001","T1090.002","T1090.003","T1090.004","T1092","T1095","T1098","T1098.004","T1098.007","T1102","T1102.001","T1102.002","T1102.003","T1104","T1105","T1106","T1110.002","T1113","T1114","T1114.003","T1115","T1119","T1120","T1123","T1124","T1125","T1129","T1132","T1132.001","T1132.002","T1133","T1135","T1136","T1136.001","T1136.002","T1140","T1176","T1176.001","T1176.002","T1189","T1190","T1195","T1195.001","T1195.002","T1195.003","T1199","T1200","T1201","T1203","T1204","T1204.001","T1204.002","T1204.003","T1204.004","T1204.005","T1205","T1205.001","T1205.002","T1210","T1211","T1212","T1213","T1213.006","T1217","T1218","T1218.015","T1219","T1219.001","T1219.002","T1219.003","T1222","T1222.002","T1480","T1480.001","T1480.002","T1485","T1486","T1489","T1490","T1491","T1491.001","T1491.002","T1495","T1496","T1496.001","T1496.002","T1497","T1497.001","T1497.002","T1497.003","T1498","T1498.001","T1498.002","T1499","T1499.001","T1499.002","T1499.003","T1499.004","T1505","T1505.001","T1505.002","T1505.003","T1518","T1518.001","T1518.002","T1529","T1531","T1534","T1539","T1542","T1542.002","T1542.003","T1543","T1543.002","T1543.005","T1546","T1546.004","T1546.005","T1546.016","T1546.017","T1546.018","T1547","T1547.006","T1547.013","T1548","T1548.001","T1548.003","T1550","T1552","T1552.001","T1552.003","T1552.004","T1553","T1553.004","T1554","T1555","T1555.002","T1555.003","T1555.005","T1556","T1556.003","T1556.006","T1557","T1557.002","T1558","T1558.005","T1559","T1560","T1560.001","T1560.002","T1560.003","T1561","T1561.001","T1561.002","T1563","T1563.001","T1564.003","T1564.005","T1564.006","T1564.007","T1564.008","T1564.011","T1564.012","T1564.013","T1564.014","T1565","T1565.001","T1565.002","T1565.003","T1566","T1566.001","T1566.002","T1566.003","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1568","T1568.001","T1568.002","T1568.003","T1569","T1569.003","T1570","T1571","T1572","T1573","T1573.001","T1573.002","T1574","T1574.006","T1574.007","T1606","T1606.001","T1611","T1614","T1614.001","T1620","T1622","T1649","T1652","T1653","T1654","T1657","T1659","T1665","T1667","T1668","T1669","T1673","T1674","T1678","T1680","T1684.001","T1685","T1685.003","T1685.004","T1685.006","T1686","T1689","T1690"],"platforms":["Containers","Linux","macOS"],"kev_cves":["CVE-2007-5659","CVE-2008-0655","CVE-2008-2992","CVE-2009-1862","CVE-2009-3953","CVE-2009-3960","CVE-2009-4324","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2011-2462","CVE-2012-0754","CVE-2012-0767","CVE-2012-1535","CVE-2012-2034","CVE-2012-5054","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0640","CVE-2013-0641","CVE-2013-3346","CVE-2014-0496","CVE-2014-0546","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-3113","CVE-2015-5119","CVE-2015-7645","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1010","CVE-2016-1019","CVE-2016-4117","CVE-2016-4437","CVE-2016-7855","CVE-2017-11292","CVE-2017-11882","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-0296","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-15982","CVE-2018-4878","CVE-2018-4939","CVE-2018-4990","CVE-2018-6789","CVE-2018-7600","CVE-2019-0211","CVE-2019-0604","CVE-2019-0708","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2019-19781","CVE-2019-3396","CVE-2019-3398","CVE-2019-5591","CVE-2020-0069","CVE-2020-0688","CVE-2020-0787","CVE-2020-12812","CVE-2020-1472","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3452","CVE-2020-3580","CVE-2020-5735","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2020-8657","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21017","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22899","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26855","CVE-2021-26857","CVE-2021-26858","CVE-2021-27059","CVE-2021-27065","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-28550","CVE-2021-29256","CVE-2021-30554","CVE-2021-31166","CVE-2021-31207","CVE-2021-3129","CVE-2021-32030","CVE-2021-33739","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-36934","CVE-2021-37415","CVE-2021-37975","CVE-2021-39144","CVE-2021-39226","CVE-2021-4034","CVE-2021-40449","CVE-2021-40539","CVE-2021-40655","CVE-2021-41379","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45046","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-1388","CVE-2022-20699","CVE-2022-20700","CVE-2022-20701","CVE-2022-20703","CVE-2022-20708","CVE-2022-20821","CVE-2022-21919","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22947","CVE-2022-22948","CVE-2022-22954","CVE-2022-22960","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24086","CVE-2022-24521","CVE-2022-24682","CVE-2022-26134","CVE-2022-26138","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-30190","CVE-2022-3038","CVE-2022-3075","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-40684","CVE-2022-41033","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2022-47966","CVE-2023-0386","CVE-2023-0669","CVE-2023-1389","CVE-2023-20109","CVE-2023-20118","CVE-2023-20198","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-2136","CVE-2023-21608","CVE-2023-21674","CVE-2023-21715","CVE-2023-22515","CVE-2023-22518","CVE-2023-22527","CVE-2023-22952","CVE-2023-23397","CVE-2023-2533","CVE-2023-26359","CVE-2023-26360","CVE-2023-26369","CVE-2023-27350","CVE-2023-27524","CVE-2023-27532","CVE-2023-27997","CVE-2023-28229","CVE-2023-28252","CVE-2023-2868","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-32315","CVE-2023-33246","CVE-2023-33538","CVE-2023-34048","CVE-2023-34192","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-39780","CVE-2023-40044","CVE-2023-41179","CVE-2023-42793","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-4966","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-6548","CVE-2023-6549","CVE-2023-7024","CVE-2023-7101","CVE-2024-0769","CVE-2024-11120","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20359","CVE-2024-20399","CVE-2024-20439","CVE-2024-20953","CVE-2024-21413","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-26169","CVE-2024-27198","CVE-2024-27443","CVE-2024-29059","CVE-2024-30051","CVE-2024-34102","CVE-2024-37085","CVE-2024-38080","CVE-2024-38112","CVE-2024-38475","CVE-2024-40890","CVE-2024-40891","CVE-2024-41710","CVE-2024-41713","CVE-2024-42009","CVE-2024-4358","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-48248","CVE-2024-4879","CVE-2024-4885","CVE-2024-49035","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-50603","CVE-2024-5217","CVE-2024-5274","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-55591","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-0411","CVE-2025-0994","CVE-2025-1316","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21480","CVE-2025-21590","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24054","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-24991","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27038","CVE-2025-27363","CVE-2025-2783","CVE-2025-30397","CVE-2025-30400","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-34028","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-48927","CVE-2025-48928","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"linux-syslog","name":"linux:syslog","channels":[{"channel":"/var/log/syslog","analytics":["AN0174","AN0211","AN0735"],"data_components":["DC0029"]},{"channel":"Accepted publickey/password for * from * port * ssh2","analytics":["AN1345"],"data_components":["DC0067"]},{"channel":"Application or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loads","analytics":["AN0499"],"data_components":["DC0038"]},{"channel":"Authentication attempts into finance-related servers from unusual IPs or times","analytics":["AN1362"],"data_components":["DC0038"]},{"channel":"Block device write errors or unusual bootloader activity","analytics":["AN0429"],"data_components":["DC0046"]},{"channel":"CLI access to 'show running-config', 'show password', or 'cat config.txt'","analytics":["AN1159"],"data_components":["DC0064"]},{"channel":"DNS response IPs followed by connections to non-standard calculated ports","analytics":["AN0729"],"data_components":["DC0085"]},{"channel":"Discrepancies in _VBA_PROJECT p-code vs source code extracted with oletools/pcodedmp","analytics":["AN0035"],"data_components":["DC0059"]},{"channel":"Driver load events or firmware load failures for hardware devices","analytics":["AN0917"],"data_components":["DC0079"]},{"channel":"Error/warning logs from services indicating load spike or worker exhaustion","analytics":["AN1166"],"data_components":["DC0038"]},{"channel":"Execution of modified binaries or abnormal library load sequences","analytics":["AN1098"],"data_components":["DC0021"]},{"channel":"Execution of non-standard script or binary by cron","analytics":["AN0025"],"data_components":["DC0001"]},{"channel":"Failed password for invalid user","analytics":["AN1337"],"data_components":["DC0002"]},{"channel":"Inbound messages from webmail services containing attachments or URLs","analytics":["AN0321"],"data_components":["DC0038"]},{"channel":"Integrity mismatch warnings or malformed packets detected","analytics":["AN0703"],"data_components":["DC0085"]},{"channel":"Kernel or daemon warnings of downgraded TLS or cryptographic settings","analytics":["AN0996"],"data_components":["DC0034"]},{"channel":"Module registration or stacktrace logs indicating segmentation faults or unknown module errors","analytics":["AN1508"],"data_components":["DC0038"]},{"channel":"Multiple NXDOMAIN responses and high entropy domains","analytics":["AN1179"],"data_components":["DC0085"]},{"channel":"New HID device enumeration with type 'keyboard' followed by immediate input injection","analytics":["AN1568"],"data_components":["DC0042"]},{"channel":"New Wi-Fi connection established or repeated association failures","analytics":["AN1477"],"data_components":["DC0082"]},{"channel":"Non-standard processes negotiating SSL/TLS key exchanges","analytics":["AN1497"],"data_components":["DC0038"]},{"channel":"None","analytics":["AN0505","AN1532","AN1638"],"data_components":["DC0067","DC0082","DC0088"]},{"channel":"Out of memory killer invoked or kernel panic entries","analytics":["AN0585"],"data_components":["DC0018"]},{"channel":"Query to suspicious domain with high entropy or low reputation","analytics":["AN0110"],"data_components":["DC0085"]},{"channel":"Repetitive HTTP 408, 500, or 503 errors logged within short timeframe","analytics":["AN0490"],"data_components":["DC0038"]},{"channel":"SPF fail OR DKIM fail OR DMARC fail OR mismatched from_domain vs return_path_domain","analytics":["AN1203"],"data_components":["DC0038"]},{"channel":"SSH failed login","analytics":["AN1263"],"data_components":["DC0002"]},{"channel":"Segfaults, kernel oops, or crashes in security software processes","analytics":["AN1634"],"data_components":["DC0038"]},{"channel":"Service restart with modified executable path","analytics":["AN0610"],"data_components":["DC0041"]},{"channel":"Service stop or disable messages for security tools not reflected in SIEM alerts","analytics":["AN0869"],"data_components":["DC0018"]},{"channel":"Sudo or root escalation followed by filesystem mount commands","analytics":["AN1272"],"data_components":["DC0064"]},{"channel":"Suspicious script or command execution targeting browser folders","analytics":["AN0038"],"data_components":["DC0064"]},{"channel":"System daemons initiating encrypted sessions with unexpected destinations","analytics":["AN0401"],"data_components":["DC0038"]},{"channel":"Unauthorized sudo or shell access, especially leading to file changes in /var/www or /srv/http","analytics":["AN0663"],"data_components":["DC0032"]},{"channel":"Unexpected SQL or application log entries showing tampered or malformed data","analytics":["AN0163"],"data_components":["DC0085"]},{"channel":"Unexpected termination of daemons or critical services not aligned with admin change tickets","analytics":["AN0046"],"data_components":["DC0033"]},{"channel":"Unusual kinit or klist activity","analytics":["AN1444"],"data_components":["DC0084"]},{"channel":"Unusual outbound transfers from CLI tools like base64, gzip, or netcat","analytics":["AN0303"],"data_components":["DC0064"]},{"channel":"application or system execution logs","analytics":["AN0812"],"data_components":["DC0059"]},{"channel":"auditd service stopped or disabled","analytics":["AN0171"],"data_components":["DC0041"]},{"channel":"auth.log / secure.log","analytics":["AN1081"],"data_components":["DC0067"]},{"channel":"auth.log or custom tool logs","analytics":["AN0293"],"data_components":["DC0055"]},{"channel":"authentication and authorization events during environmental validation phase","analytics":["AN1552"],"data_components":["DC0002"]},{"channel":"authentication success after file access","analytics":["AN0857"],"data_components":["DC0067"]},{"channel":"boot logs","analytics":["AN0658"],"data_components":["DC0029"]},{"channel":"browser/office crash, segfault, abnormal termination","analytics":["AN0798"],"data_components":["DC0038"]},{"channel":"cron activity","analytics":["AN0014"],"data_components":["DC0064"]},{"channel":"curl|wget|python .*http","analytics":["AN0148"],"data_components":["DC0085"]},{"channel":"dmesg or syslog for module loads","analytics":["AN0688"],"data_components":["DC0079"]},{"channel":"iptables or nftables rule changes","analytics":["AN0887"],"data_components":["DC0051"]},{"channel":"kernel messages related to cryptographic operations, module loading, and filesystem access patterns","analytics":["AN1306"],"data_components":["DC0055"]},{"channel":"kernel|systemd messages indicating 'segmentation fault'|'core dumped'|'service terminated unexpectedly' for sshd, smbd, vsftpd, mysqld, httpd, etc.","analytics":["AN0328"],"data_components":["DC0038"]},{"channel":"kmod","analytics":["AN1062"],"data_components":["DC0016"]},{"channel":"milter configuration updated, transport rule initialized, unexpected script execution","analytics":["AN0473"],"data_components":["DC0038"]},{"channel":"mount/umount or file copy logs","analytics":["AN1146"],"data_components":["DC0054"]},{"channel":"network","analytics":["AN1016","AN1584"],"data_components":["DC0082"]},{"channel":"opened document|clicked link|segfault|abnormal termination|sandbox","analytics":["AN1315"],"data_components":["DC0038"]},{"channel":"postfix/smtpd","analytics":["AN1310"],"data_components":["DC0082"]},{"channel":"processes binding to non-standard ports or sshd configured on unexpected port","analytics":["AN0634"],"data_components":["DC0038"]},{"channel":"rename","analytics":["AN0356"],"data_components":["DC0061"]},{"channel":"service stopped messages","analytics":["AN0062"],"data_components":["DC0041"]},{"channel":"sshd logs","analytics":["AN1026"],"data_components":["DC0064"]},{"channel":"sshd sessions with unusual port forwarding parameters","analytics":["AN1484"],"data_components":["DC0038"]},{"channel":"sshd: Accepted password/publickey","analytics":["AN0751"],"data_components":["DC0067"]},{"channel":"sshd[pid]: Failed password","analytics":["AN1522"],"data_components":["DC0002"]},{"channel":"sssd / sudo logs","analytics":["AN0591"],"data_components":["DC0088"]},{"channel":"sudo chage|grep pam_pwquality|cat /etc/login.defs","analytics":["AN0456"],"data_components":["DC0064"]},{"channel":"sudo execution of ffmpeg/gst-launch/v4l2-ctl by non-standard user","analytics":["AN0569"],"data_components":["DC0064"]},{"channel":"sudo or service accounts invoking loaders with suspicious env vars","analytics":["AN0053"],"data_components":["DC0034"]},{"channel":"sudo or su access prior to content change","analytics":["AN0230"],"data_components":["DC0010"]},{"channel":"sudo/date/timedatectl execution by non-standard users","analytics":["AN0431"],"data_components":["DC0002"]},{"channel":"suspicious DHCP lease assignment with unexpected DNS or gateway","analytics":["AN1291"],"data_components":["DC0038"]},{"channel":"syscalls (open, read, ioctl) on /dev/input or /proc/*/fd/*","analytics":["AN0688"],"data_components":["DC0035"]},{"channel":"system daemons initiating TLS sessions outside expected services","analytics":["AN0760"],"data_components":["DC0038"]},{"channel":"system is powering down","analytics":["AN1539"],"data_components":["DC0018"]},{"channel":"systemctl start/enable with uncommon binary paths","analytics":["AN0779"],"data_components":["DC0060"]},{"channel":"usb * new|thunderbolt|pci .* added|block.*: new .* device","analytics":["AN0186"],"data_components":["DC0038"]}],"data_components":["DC0001","DC0002","DC0010","DC0016","DC0018","DC0021","DC0029","DC0032","DC0033","DC0034","DC0035","DC0038","DC0041","DC0042","DC0046","DC0051","DC0054","DC0055","DC0059","DC0060","DC0061","DC0064","DC0067","DC0079","DC0082","DC0084","DC0085","DC0088"],"analytics":["AN0014","AN0025","AN0035","AN0038","AN0046","AN0053","AN0062","AN0110","AN0148","AN0163","AN0171","AN0174","AN0186","AN0211","AN0230","AN0293","AN0303","AN0321","AN0328","AN0356","AN0401","AN0429","AN0431","AN0456","AN0473","AN0490","AN0499","AN0505","AN0569","AN0585","AN0591","AN0610","AN0634","AN0658","AN0663","AN0688","AN0703","AN0729","AN0735","AN0751","AN0760","AN0779","AN0798","AN0812","AN0857","AN0869","AN0887","AN0917","AN0996","AN1016","AN1026","AN1062","AN1081","AN1098","AN1146","AN1159","AN1166","AN1179","AN1203","AN1263","AN1272","AN1291","AN1306","AN1310","AN1315","AN1337","AN1345","AN1362","AN1444","AN1477","AN1484","AN1497","AN1508","AN1522","AN1532","AN1539","AN1552","AN1568","AN1584","AN1634","AN1638"],"techniques":["T1011.001","T1014","T1016.001","T1018","T1021","T1021.004","T1021.005","T1036","T1036.003","T1036.006","T1037.004","T1039","T1059.004","T1059.005","T1059.006","T1059.007","T1069.002","T1078.002","T1110.001","T1110.002","T1110.003","T1110.004","T1111","T1114","T1124","T1125","T1129","T1132","T1189","T1199","T1200","T1201","T1203","T1204","T1210","T1211","T1217","T1480","T1480.001","T1489","T1491","T1491.001","T1499","T1499.002","T1499.003","T1505","T1505.002","T1529","T1534","T1542.002","T1542.003","T1546","T1552","T1552.001","T1557.003","T1558","T1564.005","T1564.007","T1565","T1565.002","T1565.003","T1566.003","T1568","T1568.002","T1568.003","T1569","T1571","T1572","T1573","T1573.001","T1573.002","T1574","T1657","T1668","T1669","T1674","T1684.002","T1685.003","T1685.004","T1689"],"platforms":["Linux","Network Devices"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2013-3346","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-10033","CVE-2016-1010","CVE-2016-1019","CVE-2016-7855","CVE-2017-6742","CVE-2018-4939","CVE-2018-4990","CVE-2019-0708","CVE-2019-11510","CVE-2020-0688","CVE-2020-1472","CVE-2020-3580","CVE-2020-5735","CVE-2020-5902","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-31207","CVE-2021-35394","CVE-2021-36380","CVE-2021-37975","CVE-2021-39144","CVE-2021-40449","CVE-2021-40539","CVE-2021-41773","CVE-2021-42013","CVE-2021-44077","CVE-2021-45382","CVE-2022-1040","CVE-2022-20699","CVE-2022-20700","CVE-2022-20701","CVE-2022-20703","CVE-2022-21999","CVE-2022-22963","CVE-2022-23748","CVE-2022-24682","CVE-2022-26138","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-3038","CVE-2022-41073","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-43769","CVE-2023-0669","CVE-2023-20109","CVE-2023-21608","CVE-2023-22515","CVE-2023-23397","CVE-2023-26360","CVE-2023-26369","CVE-2023-27997","CVE-2023-28252","CVE-2023-34048","CVE-2023-3519","CVE-2023-36844","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-39780","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-47565","CVE-2023-49103","CVE-2023-4966","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-6549","CVE-2023-7024","CVE-2024-11120","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20439","CVE-2024-21762","CVE-2024-21887","CVE-2024-24919","CVE-2024-26169","CVE-2024-27443","CVE-2024-38112","CVE-2024-42009","CVE-2024-45195","CVE-2024-4671","CVE-2024-4947","CVE-2024-5274","CVE-2024-53704","CVE-2024-54085","CVE-2024-55591","CVE-2024-57727","CVE-2025-0282","CVE-2025-24016","CVE-2025-24201","CVE-2025-24993","CVE-2025-25257","CVE-2025-27038","CVE-2025-27363","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31200","CVE-2025-31201","CVE-2025-32433","CVE-2025-3248","CVE-2025-34028","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-49706","CVE-2025-5419","CVE-2025-54309","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"linux-sysmon","name":"linux:Sysmon","channels":[{"channel":"EventCode=1","analytics":["AN0120","AN0620","AN0847","AN1562","AN1613","AN1631"],"data_components":["DC0032"]},{"channel":"EventCode=3, 22","analytics":["AN0238","AN1161"],"data_components":["DC0082"]},{"channel":"EventCode=7","analytics":["AN0473"],"data_components":["DC0016"]},{"channel":"New files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetch","analytics":["AN0499"],"data_components":["DC0039"]},{"channel":"process creation events linked to container namespaces executing host-level binaries","analytics":["AN0613"],"data_components":["DC0032"]}],"data_components":["DC0016","DC0032","DC0039","DC0082"],"analytics":["AN0120","AN0238","AN0473","AN0499","AN0613","AN0620","AN0847","AN1161","AN1562","AN1613","AN1631"],"techniques":["T1003.007","T1027.013","T1087","T1087.001","T1123","T1189","T1213","T1505.002","T1611","T1614","T1614.001"],"platforms":["Linux"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2021-44515","CVE-2022-24086","CVE-2022-41082","CVE-2023-27532","CVE-2023-35078","CVE-2023-43770","CVE-2023-7024","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-38112","CVE-2024-4671","CVE-2024-4947","CVE-2024-5274","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-24201","CVE-2025-5419","CVE-2025-6554","CVE-2025-6558"]},{"slug":"macos-unifiedlog","name":"macos:unifiedlog","channels":[{"channel":"*.opvault OR *.ldb OR *.kdbx","analytics":["AN1643"],"data_components":["DC0055"]},{"channel":"ARP table updates inconsistent with expected gateway or DHCP lease assignments","analytics":["AN1093"],"data_components":["DC0078"]},{"channel":"Abnormal memory operations (XOR/bitwise loops) during archive generation","analytics":["AN1215"],"data_components":["DC0020"]},{"channel":"Abnormal process access to Safari or Chrome cookie storage","analytics":["AN0486"],"data_components":["DC0055"]},{"channel":"Abnormal terminations of com.apple.security.* or 3rd-party security daemons","analytics":["AN1635"],"data_components":["DC0038"]},{"channel":"Access decisions to kTCCServiceCamera for unexpected binaries","analytics":["AN0570"],"data_components":["DC0021"]},{"channel":"Access to Keychain items or browser credential stores","analytics":["AN0721"],"data_components":["DC0067"]},{"channel":"Access to ~/Library/*/Safari or Chrome directories by non-browser processes","analytics":["AN0039"],"data_components":["DC0055"]},{"channel":"Access to ~/Library/Safari/Bookmarks.plist or recent files","analytics":["AN1184"],"data_components":["DC0055"]},{"channel":"Anomalous dyld dynamic library loads or RWX memory mappings in browser process","analytics":["AN0500"],"data_components":["DC0020"]},{"channel":"Anomalous keychain access attempts targeting payment credentials","analytics":["AN1363"],"data_components":["DC0038"]},{"channel":"Anomalous plist modifications or sensitive file overwrites by non-standard processes","analytics":["AN0164"],"data_components":["DC0061"]},{"channel":"App/web server logs ingested via unified logging or filebeat (nginx/apache/node).","analytics":["AN0221"],"data_components":["DC0038"]},{"channel":"AppleScript creating login item via 'System Events' dictionary","analytics":["AN0340"],"data_components":["DC0029"]},{"channel":"Application errors or resource contention from excessive frontend or script invocation","analytics":["AN1167"],"data_components":["DC0038"]},{"channel":"Association and authentication events including failures and new SSIDs","analytics":["AN1478"],"data_components":["DC0082"]},{"channel":"Attachment files written to ~/Downloads or temporary folders","analytics":["AN0657"],"data_components":["DC0039"]},{"channel":"Authentication inconsistencies where commands are executed without corresponding login events","analytics":["AN0218"],"data_components":["DC0067"]},{"channel":"Browser processes launching unexpected interpreters (osascript, bash)","analytics":["AN0300"],"data_components":["DC0032"]},{"channel":"Calls to AuthorizationExecuteWithPrivileges() observed via Apple System Logger or security_auditing tools","analytics":["AN1111"],"data_components":["DC0021"]},{"channel":"Child processes of Safari, Chrome, or Firefox executing scripting interpreters","analytics":["AN0994"],"data_components":["DC0032"]},{"channel":"Code Execution & Entitlement Access","analytics":["AN0650"],"data_components":["DC0034"]},{"channel":"Code signature validation fails or is absent post-binary modification","analytics":["AN0607"],"data_components":["DC0059"]},{"channel":"Code signing verification failures or bypassed trust decisions","analytics":["AN0644"],"data_components":["DC0059"]},{"channel":"Command line containing `trap` or `echo 'trap` written to login shell files","analytics":["AN1039"],"data_components":["DC0032"]},{"channel":"Command line contains smbutil view //, mount_smbfs //","analytics":["AN0515"],"data_components":["DC0064"]},{"channel":"Command line invocation of pip3, brew install, npm install from interactive Terminal","analytics":["AN0700"],"data_components":["DC0032"]},{"channel":"Configuration profile modified or new profile installed","analytics":["AN0825"],"data_components":["DC0038"]},{"channel":"Connections to suspicious domains with mismatched certificate or unusual patterns","analytics":["AN0300"],"data_components":["DC0085"]},{"channel":"Crash log entries for a process receiving malformed input or known exploit patterns","analytics":["AN0852"],"data_components":["DC0038"]},{"channel":"Crash or abnormal termination of security agent or system extension host","analytics":["AN2040"],"data_components":["DC0034"]},{"channel":"Creation of .plist under /Library/Managed Preferences/","analytics":["AN0252"],"data_components":["DC0039"]},{"channel":"Creation of .zip or .dmg files in user-accessible or temporary directories","analytics":["AN1460"],"data_components":["DC0039"]},{"channel":"Creation of .zip, .dmg, .tar.gz files in /Users, /tmp, or application directories","analytics":["AN0833"],"data_components":["DC0039"]},{"channel":"Creation of .zip, .gz, .dmg archives in /Users, /tmp, or application directories","analytics":["AN0749"],"data_components":["DC0039"]},{"channel":"Creation of LaunchAgents/LaunchDaemons in hidden or non-standard directories","analytics":["AN1386"],"data_components":["DC0039"]},{"channel":"Creation of files with anomalous headers and entropy values","analytics":["AN1215"],"data_components":["DC0039"]},{"channel":"Creation of new LaunchAgent or LoginItem plist files in ~/Library/LaunchAgents/","analytics":["AN0700"],"data_components":["DC0059"]},{"channel":"Creation of user account with UID <500","analytics":["AN1003"],"data_components":["DC0013"]},{"channel":"Creation or modification of browser extension .plist files","analytics":["AN0124"],"data_components":["DC0039"]},{"channel":"Creation or modification of postinstall scripts within .pkg or .mpkg contents","analytics":["AN0938"],"data_components":["DC0039"]},{"channel":"DNS query with pseudo-random subdomain patterns","analytics":["AN0111"],"data_components":["DC0085"]},{"channel":"DNS responses followed by connections to ports outside standard ranges","analytics":["AN0730"],"data_components":["DC0085"]},{"channel":"DS daemon log entries","analytics":["AN0365"],"data_components":["DC0064"]},{"channel":"DYLD event subsystem","analytics":["AN0391"],"data_components":["DC0016"]},{"channel":"Detection of altered _VBA_PROJECT or PerformanceCache streams","analytics":["AN0036"],"data_components":["DC0059"]},{"channel":"Device attached|enumerated VID/PID","analytics":["AN0187"],"data_components":["DC0038"]},{"channel":"DirectoryService queries retrieving account information","analytics":["AN1614"],"data_components":["DC0013"]},{"channel":"Dylib loaded from abnormal location","analytics":["AN0611"],"data_components":["DC0016"]},{"channel":"EFI firmware integrity check failed","analytics":["AN1037"],"data_components":["DC0018"]},{"channel":"Electron app spawning unexpected child process","analytics":["AN0073"],"data_components":["DC0032"]},{"channel":"Encrypted connection with anomalous payload entropy","analytics":["AN0402"],"data_components":["DC0085"]},{"channel":"Encrypted session initiation by unexpected binary","analytics":["AN0761"],"data_components":["DC0085"]},{"channel":"Execution of 'profiles install -type=configuration'","analytics":["AN0252"],"data_components":["DC0064"]},{"channel":"Execution of /usr/bin/security add-trusted-cert or keychain modifications to System.keychain","analytics":["AN0155"],"data_components":["DC0064"]},{"channel":"Execution of /usr/libexec/security_authtrampoline or child processes originating from non-trusted binaries triggering credential prompts","analytics":["AN1111"],"data_components":["DC0032"]},{"channel":"Execution of /usr/sbin/installer spawning child process from within /private/tmp or package contents","analytics":["AN0938"],"data_components":["DC0032"]},{"channel":"Execution of Code.app, idea, JetBrainsToolbox, eclipse with install/extension flags","analytics":["AN1550"],"data_components":["DC0032"]},{"channel":"Execution of Java apps or other processes with hidden window attributes","analytics":["AN0362"],"data_components":["DC0032"]},{"channel":"Execution of Python, Swift, or other binaries invoking archiving libraries","analytics":["AN0749"],"data_components":["DC0032"]},{"channel":"Execution of Terminal, osascript, or other interpreters originating from Mail or Preview","analytics":["AN0657"],"data_components":["DC0032"]},{"channel":"Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond","analytics":["AN1474"],"data_components":["DC0032"]},{"channel":"Execution of binaries with unsigned or anomalously signed certificates","analytics":["AN0644"],"data_components":["DC0032"]},{"channel":"Execution of binary listed in newly modified LaunchAgent plist","analytics":["AN0766"],"data_components":["DC0032"]},{"channel":"Execution of bless or nvram modifying boot parameters","analytics":["AN0776"],"data_components":["DC0032"]},{"channel":"Execution of chflags hidden or SetFile -a V","analytics":["AN0093"],"data_components":["DC0064"]},{"channel":"Execution of chflags hidden or setfile -a V","analytics":["AN1386"],"data_components":["DC0064"]},{"channel":"Execution of commands like `ls -l@`, `xattr -l`, or custom tools interacting with resource forks","analytics":["AN1609"],"data_components":["DC0064"]},{"channel":"Execution of diskutil or hdiutil attaching hidden partitions","analytics":["AN1273"],"data_components":["DC0032"]},{"channel":"Execution of dscl . create with IsHidden=1","analytics":["AN1003"],"data_components":["DC0064"]},{"channel":"Execution of input detection APIs (e.g., CGEventSourceKeyState)","analytics":["AN1184"],"data_components":["DC0021"]},{"channel":"Execution of launchctl unload, kill, or removal of security agent daemons","analytics":["AN1371"],"data_components":["DC0032"]},{"channel":"Execution of launchctl with setenv or bootout targeting TCC.db or AppleScript under Finder context","analytics":["AN1474"],"data_components":["DC0064"]},{"channel":"Execution of launchctl with suspicious arguments","analytics":["AN0026"],"data_components":["DC0032"]},{"channel":"Execution of log show, fs_usage, or cat targeting system.log","analytics":["AN0707"],"data_components":["DC0064"]},{"channel":"Execution of older or non-standard interpreters","analytics":["AN0997"],"data_components":["DC0032"]},{"channel":"Execution of osascript, bash, or Terminal initiated from Mail.app or Safari","analytics":["AN0322"],"data_components":["DC0032"]},{"channel":"Execution of osascript, sh, bash, zsh, installer, open","analytics":["AN2036","AN2065"],"data_components":["DC0064"]},{"channel":"Execution of ping, nping, or crafted network packets via bash or python to reflection services","analytics":["AN1142"],"data_components":["DC0032"]},{"channel":"Execution of process launched via loginwindow session restore","analytics":["AN0349"],"data_components":["DC0032"]},{"channel":"Execution of process with DYLD_INSERT_LIBRARIES set","analytics":["AN0611"],"data_components":["DC0032"]},{"channel":"Execution of processes linked to hijacked sessions (e.g., anomalous parent-child process lineage)","analytics":["AN0218"],"data_components":["DC0032"]},{"channel":"Execution of processes mimicking Apple Security & Privacy GUIs","analytics":["AN0870"],"data_components":["DC0032"]},{"channel":"Execution of scp, rsync, curl with remote destination","analytics":["AN0518"],"data_components":["DC0032"]},{"channel":"Execution of ssh or sftp without corresponding login event","analytics":["AN0711"],"data_components":["DC0032"]},{"channel":"Execution of system_profiler or osascript invoking enumeration","analytics":["AN1102"],"data_components":["DC0032"]},{"channel":"Execution of unexpected terminal or web scripts modifying /Library/WebServer/Documents","analytics":["AN0664"],"data_components":["DC0032"]},{"channel":"Execution of zip, ditto, hdiutil, or openssl by non-terminal parent processes","analytics":["AN1460"],"data_components":["DC0032"]},{"channel":"Execution of zip, ditto, hdiutil, or openssl by processes not normally associated with archiving","analytics":["AN0833"],"data_components":["DC0032"]},{"channel":"Extension disabled, unloaded, failed to start","analytics":["AN2040"],"data_components":["DC0074"]},{"channel":"File Events","analytics":["AN0874"],"data_components":["DC0039"]},{"channel":"File created in ~/Library/LaunchAgents or executable directories","analytics":["AN0518"],"data_components":["DC0039"]},{"channel":"File creation","analytics":["AN0653"],"data_components":["DC0039"]},{"channel":"File creation of unsigned binaries/scripts in user cache or download directories","analytics":["AN0994"],"data_components":["DC0039"]},{"channel":"File creation or modification with com.apple.ResourceFork extended attribute","analytics":["AN1609"],"data_components":["DC0059"]},{"channel":"File creation or overwrite in common web-hosting folders","analytics":["AN0664"],"data_components":["DC0061"]},{"channel":"File metadata updated with UF_HIDDEN flag","analytics":["AN0093"],"data_components":["DC0059"]},{"channel":"File modification in /etc/paths.d or user shell rc files","analytics":["AN0011"],"data_components":["DC0061"]},{"channel":"File write or append to .zshrc, .bash_profile, .zprofile, etc.","analytics":["AN1039"],"data_components":["DC0061"]},{"channel":"Firewall rule enable/disable or listen socket changes","analytics":["AN1450"],"data_components":["DC0078"]},{"channel":"Firewall/PF anchor load or rule change events.","analytics":["AN0844"],"data_components":["DC0078"]},{"channel":"Firmware update events or kernel extension (kext) loads not signed by Apple","analytics":["AN0918"],"data_components":["DC0004"]},{"channel":"First outbound connection from the same PID/user shortly after an inbound trigger.","analytics":["AN0464"],"data_components":["DC0082"]},{"channel":"Group membership change for admin or wheel","analytics":["AN1346"],"data_components":["DC0088"]},{"channel":"HTTP POST with encoded content in user-agent or cookie field","analytics":["AN0304"],"data_components":["DC0085"]},{"channel":"HTTPS POST requests to pastebin.com or similar","analytics":["AN0789"],"data_components":["DC0078"]},{"channel":"HTTPS POST to known webhook URLs","analytics":["AN0438"],"data_components":["DC0078"]},{"channel":"Hardware enumeration events via IOKit or USBMuxd showing TinyPilot or unknown keyboard/mouse","analytics":["AN0448"],"data_components":["DC0042"]},{"channel":"Hidden volume attachment or modification events","analytics":["AN1273"],"data_components":["DC0061"]},{"channel":"High entropy domain queries with multiple NXDOMAINs","analytics":["AN1180"],"data_components":["DC0078"]},{"channel":"IOKit disk write calls targeting raw devices","analytics":["AN0386"],"data_components":["DC0046"]},{"channel":"IOKit raw disk write activity targeting physical devices","analytics":["AN0884"],"data_components":["DC0046"]},{"channel":"IOKit raw disk write to EFI/boot partition sectors","analytics":["AN0829"],"data_components":["DC0046"]},{"channel":"Inbound connections to VNC/SSH ports","analytics":["AN1006"],"data_components":["DC0082"]},{"channel":"Inbound email activity with suspicious domains or mismatched sender information","analytics":["AN0190"],"data_components":["DC0038"]},{"channel":"Inbound messages with attachments from suspicious domains","analytics":["AN0657"],"data_components":["DC0038"]},{"channel":"Invocation of SMLoginItemSetEnabled by non-system or recently installed application","analytics":["AN0340"],"data_components":["DC0021"]},{"channel":"Kerberos framework calls to API:{uuid} cache outside normal process lineage","analytics":["AN0070"],"data_components":["DC0055"]},{"channel":"Keychain or user login post-access","analytics":["AN0858"],"data_components":["DC0067"]},{"channel":"Loading of libz.dylib, libarchive.dylib by non-standard applications","analytics":["AN0749"],"data_components":["DC0016"]},{"channel":"Login Window and Authd errors","analytics":["AN1338"],"data_components":["DC0002"]},{"channel":"Login failure / authorization denied","analytics":["AN1264"],"data_components":["DC0002"]},{"channel":"Login success without MFA step","analytics":["AN0547"],"data_components":["DC0002"]},{"channel":"LoginWindow context with associated PID linked to reopened plist paths","analytics":["AN0349"],"data_components":["DC0088"]},{"channel":"Logs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches","analytics":["AN0500"],"data_components":["DC0038"]},{"channel":"Mach-O binary modified or LC_LOAD_DYLIB segment inserted","analytics":["AN0607"],"data_components":["DC0061"]},{"channel":"Mail or AppleScript subsystem","analytics":["AN1311"],"data_components":["DC0038"]},{"channel":"Mail.app executing with parameters updating rules state","analytics":["AN0552"],"data_components":["DC0032"]},{"channel":"Mail.app or third-party clients sending messages with mismatched From headers","analytics":["AN0794"],"data_components":["DC0038"]},{"channel":"Modification of /Library/Preferences/com.apple.loginwindow plist","analytics":["AN1003"],"data_components":["DC0061"]},{"channel":"Modification of /Library/Security/SecurityAgentPlugins","analytics":["AN0547"],"data_components":["DC0061"]},{"channel":"Modification of /System/Library/CoreServices/boot.efi","analytics":["AN0776"],"data_components":["DC0061"]},{"channel":"Modification of LaunchAgents or LaunchDaemons plist files","analytics":["AN0780"],"data_components":["DC0061"]},{"channel":"Modification of backgrounditems.btm or creation of LoginItems subdirectory in .app bundle","analytics":["AN0340"],"data_components":["DC0061"]},{"channel":"Modification of plist with apple.awt.UIElement set to TRUE","analytics":["AN0362"],"data_components":["DC0061"]},{"channel":"Modification of system configuration profiles affecting security tools","analytics":["AN1371"],"data_components":["DC0041"]},{"channel":"Modification of ~/Library/LaunchAgents or /Library/LaunchDaemons plist","analytics":["AN0026"],"data_components":["DC0061"]},{"channel":"Modification or replacement of /Library/Application Support/com.apple.TCC/TCC.db or ~/Library/Application Support/com.apple.TCC/TCC.db","analytics":["AN1474"],"data_components":["DC0061"]},{"channel":"Modifications or writes to EFI system partition for downgraded bootloaders","analytics":["AN0997"],"data_components":["DC0034"]},{"channel":"Modifications to Mail.app plist files controlling message rules","analytics":["AN0552"],"data_components":["DC0061"]},{"channel":"Modified application plist or binary replacement in /Applications","analytics":["AN0611"],"data_components":["DC0061"]},{"channel":"New IOUSB keyboard/HID device enumerated with suspicious attributes","analytics":["AN1569"],"data_components":["DC0042"]},{"channel":"New certificate trust settings added by unexpected process","analytics":["AN1248"],"data_components":["DC0059"]},{"channel":"New files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children","analytics":["AN0500"],"data_components":["DC0039"]},{"channel":"New session initiated using cookies without normal MFA or password validation","analytics":["AN0486"],"data_components":["DC0007"]},{"channel":"New/modified launchd plist (persistence/scheduling) within TimeWindow after time query","analytics":["AN0432"],"data_components":["DC0005"]},{"channel":"Non-standard processes invoking financial applications or payment APIs","analytics":["AN1363"],"data_components":["DC0032"]},{"channel":"None","analytics":["AN0206","AN0214","AN0273","AN0848","AN1231","AN1327","AN1378","AN1533"],"data_components":["DC0021","DC0032","DC0064","DC0082","DC0085"]},{"channel":"Observed loading of new LaunchAgent or LaunchDaemon plist","analytics":["AN0766"],"data_components":["DC0041"]},{"channel":"Outbound Traffic","analytics":["AN1296"],"data_components":["DC0082"]},{"channel":"Outbound UDP spikes to external reflector IPs","analytics":["AN1142"],"data_components":["DC0078"]},{"channel":"Outbound connections from IDE processes to marketplace/tunnel domains","analytics":["AN1550"],"data_components":["DC0078"]},{"channel":"Outgoing or incoming calls with non-standard caller IDs or unusual metadata","analytics":["AN0685"],"data_components":["DC0038"]},{"channel":"Persistent outbound connections with consistent periodicity","analytics":["AN1491"],"data_components":["DC0085"]},{"channel":"Persistent outbound traffic to mining domains","analytics":["AN0743"],"data_components":["DC0085"]},{"channel":"Plist modifications containing virtualization run configurations","analytics":["AN0911"],"data_components":["DC0061"]},{"channel":"Post-login execution of unrecognized child process from launchd or loginwindow","analytics":["AN0340"],"data_components":["DC0032"]},{"channel":"Preview.app, Safari.app, or Mail.app spawning new processes outside normal patterns","analytics":["AN0190"],"data_components":["DC0032"]},{"channel":"Process Execution","analytics":["AN0365"],"data_components":["DC0032"]},{"channel":"Process creation events where command line = pmset with arguments affecting sleep, hibernatemode, displaysleep","analytics":["AN1176"],"data_components":["DC0032"]},{"channel":"Process creation involving binaries interacting with resource fork data","analytics":["AN1609"],"data_components":["DC0032"]},{"channel":"Process creation with parent PID of 1 (launchd)","analytics":["AN1224"],"data_components":["DC0032"]},{"channel":"Process exec of remote-control apps or binaries with headless/connect flags","analytics":["AN1368"],"data_components":["DC0032"]},{"channel":"Process execution for VBoxHeadless, prl_vm_app, vmware-vmx","analytics":["AN0911"],"data_components":["DC0032"]},{"channel":"Process execution logs showing discovery commands like mdfind, system_profiler, or launchctl list","analytics":["AN0242"],"data_components":["DC0032"]},{"channel":"Process execution of Microsoft Word, Excel, PowerPoint with macro execution attempts","analytics":["AN0036"],"data_components":["DC0032"]},{"channel":"Process execution or directory service changes","analytics":["AN0867"],"data_components":["DC0010"]},{"channel":"Process execution path inconsistent with baseline PATH directories","analytics":["AN0011"],"data_components":["DC0032"]},{"channel":"Process invoking SSL routines from Security framework","analytics":["AN0761"],"data_components":["DC0032"]},{"channel":"Process invoking SecKeyCreateRandomKey or asymmetric crypto APIs","analytics":["AN1498"],"data_components":["DC0032"]},{"channel":"Process launch","analytics":["AN0784"],"data_components":["DC0032"]},{"channel":"Process memory maps new dylib (dylib_load event)","analytics":["AN0607"],"data_components":["DC0016"]},{"channel":"Process opening SSH_AUTH_SOCK or /tmp/ssh-* socket not owned by same UID","analytics":["AN0711"],"data_components":["DC0034"]},{"channel":"Process start of Java or native DB client tools","analytics":["AN0678"],"data_components":["DC0032"]},{"channel":"Process using AES/RC4 routines unexpectedly","analytics":["AN0402"],"data_components":["DC0032"]},{"channel":"Process wrote large .mov/.mp4 in user temp/hidden dirs","analytics":["AN0570"],"data_components":["DC0039"]},{"channel":"Rapid domain-to-IP resolution changes for same domain","analytics":["AN1333"],"data_components":["DC0078"]},{"channel":"Rapid incoming TLS handshakes or HTTP requests in quick succession","analytics":["AN0491"],"data_components":["DC0085"]},{"channel":"Read access to Time Machine plist files or CCC configurations in ~/Library/Preferences/","analytics":["AN0242"],"data_components":["DC0055"]},{"channel":"Received messages containing embedded links or attachments from non-enterprise services","analytics":["AN0322"],"data_components":["DC0038"]},{"channel":"Received messages with embedded or shortened URLs","analytics":["AN0300"],"data_components":["DC0038"]},{"channel":"Recent download opened or executed","analytics":["AN2036"],"data_components":["DC0055"]},{"channel":"Remote login (ssh) or screen sharing authentication attempts","analytics":["AN1006"],"data_components":["DC0088"]},{"channel":"Repeated process crashes logged by CrashReporter or system instability logs in com.apple.console","analytics":["AN0586"],"data_components":["DC0038"]},{"channel":"Repetitive inbound email delivery activity logged within a short time window","analytics":["AN1011"],"data_components":["DC0038"]},{"channel":"SPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domains","analytics":["AN1204"],"data_components":["DC0038"]},{"channel":"Script interpreter invoked by nginx/apache worker process","analytics":["AN1509"],"data_components":["DC0032"]},{"channel":"Security framework operations including keychain access, cryptographic operations, and certificate validation","analytics":["AN1307"],"data_components":["DC0064"]},{"channel":"SecurityAgentPlugins modification","analytics":["AN0289"],"data_components":["DC0061"]},{"channel":"Session reuse without new auth event","analytics":["AN0711"],"data_components":["DC0067"]},{"channel":"Set or unset HIST* variables in shell environment","analytics":["AN1556"],"data_components":["DC0064"]},{"channel":"Spike in CPU or memory use from non-user-initiated processes","analytics":["AN0586"],"data_components":["DC0018"]},{"channel":"Suspicious Swift/Objective-C or scripting processes writing archive-like outputs","analytics":["AN1215"],"data_components":["DC0032"]},{"channel":"Suspicious anomalies in transmitted data integrity during application network operations","analytics":["AN0704"],"data_components":["DC0078"]},{"channel":"Suspicious outbound HTTPS requests to domains flagged as newly registered or untrusted after spearphishing message interaction","analytics":["AN0322"],"data_components":["DC0085"]},{"channel":"Suspicious outbound traffic from browser binary to non-standard domains","analytics":["AN0252"],"data_components":["DC0078"]},{"channel":"System Integrity Protection (SIP) state reported as disabled","analytics":["AN1474"],"data_components":["DC0018"]},{"channel":"System process modifications altering DNS/proxy settings","analytics":["AN1150"],"data_components":["DC0032"]},{"channel":"System shutdown or reboot requested","analytics":["AN1540"],"data_components":["DC0018"]},{"channel":"TLS connections with abnormal handshake sequence or self-signed cert","analytics":["AN1498"],"data_components":["DC0085"]},{"channel":"Terminal process killed (killall Terminal) immediately after sudoers modification","analytics":["AN0143"],"data_components":["DC0033"]},{"channel":"Terminal/Editor processes modifying web folder","analytics":["AN1624"],"data_components":["DC0061"]},{"channel":"Termination of syspolicyd or XProtect processes","analytics":["AN0888"],"data_components":["DC0033"]},{"channel":"Termination or disabling of XProtect, Gatekeeper, or third-party AV daemons","analytics":["AN0870"],"data_components":["DC0018"]},{"channel":"Trust validation failures or bypass attempts during notarization and code signing checks","analytics":["AN0800"],"data_components":["DC0032"]},{"channel":"Unexpected NSXPCConnection calls by non-Apple-signed or abnormal binaries","analytics":["AN0948"],"data_components":["DC0035"]},{"channel":"Unexpected application binary modifications or altered signing status","analytics":["AN1099"],"data_components":["DC0059"]},{"channel":"Unexpected applications generating outbound DNS queries","analytics":["AN0111"],"data_components":["DC0032"]},{"channel":"Unexpected apps generating frequent DNS queries","analytics":["AN1333"],"data_components":["DC0032"]},{"channel":"Unexpected apps performing repeated DNS lookups","analytics":["AN1180"],"data_components":["DC0032"]},{"channel":"Unexpected child process of Safari or Chrome","analytics":["AN0124"],"data_components":["DC0032"]},{"channel":"Unexpected creation or modification of stored data files in protected directories","analytics":["AN0557"],"data_components":["DC0061"]},{"channel":"Unexpected processes making network calls based on DNS-derived ports","analytics":["AN0730"],"data_components":["DC0032"]},{"channel":"Unexpected processes registered with launchd","analytics":["AN0780"],"data_components":["DC0032"]},{"channel":"Unsigned binary execution following SIP change","analytics":["AN1447"],"data_components":["DC0032"]},{"channel":"Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime","analytics":["AN1445"],"data_components":["DC0088"]},{"channel":"Unusual Mach port registration or access attempts between unrelated processes","analytics":["AN1359"],"data_components":["DC0035"]},{"channel":"Unusual child process tree indicating attempted recovery after crash","analytics":["AN0852"],"data_components":["DC0032"]},{"channel":"User credential prompt events without associated trusted installer package","analytics":["AN1111"],"data_components":["DC0002"]},{"channel":"UserLoggedIn","analytics":["AN0008"],"data_components":["DC0067"]},{"channel":"Volume Mount + File Read","analytics":["AN0344"],"data_components":["DC0042"]},{"channel":"Volume Mount + Process Trace + File Read","analytics":["AN0618"],"data_components":["DC0042"]},{"channel":"Web server process initiating outbound TCP connections not tied to normal server traffic","analytics":["AN1509"],"data_components":["DC0085"]},{"channel":"Web service process (e.g., httpd) entering crash loop or consuming excessive CPU","analytics":["AN0491"],"data_components":["DC0018"]},{"channel":"Web sessions initiated with newly forged tokens","analytics":["AN0721"],"data_components":["DC0007"]},{"channel":"Writes of .sql/.csv/.xlsx files to user documents/downloads","analytics":["AN0678"],"data_components":["DC0039"]},{"channel":"Writes under ~/Library/Application Support/Code*/extensions or JetBrains plugins","analytics":["AN1550"],"data_components":["DC0039"]},{"channel":"XPC messages requesting privileged actions from untrusted or unsigned clients","analytics":["AN0948"],"data_components":["DC0048"]},{"channel":"access or unlock attempt to keychain database","analytics":["AN1112"],"data_components":["DC0021"]},{"channel":"access to /Volumes/SharePoint or network mount","analytics":["AN1163"],"data_components":["DC0055"]},{"channel":"access to keychain database","analytics":["AN1200"],"data_components":["DC0055"]},{"channel":"application logs referencing NSTimer, sleep, or launchd delays","analytics":["AN0398"],"data_components":["DC0021"]},{"channel":"audio APIs","analytics":["AN0621"],"data_components":["DC0021"]},{"channel":"auth","analytics":["AN1278"],"data_components":["DC0002"]},{"channel":"authd","analytics":["AN1523"],"data_components":["DC0002"]},{"channel":"authd generating multiple MFA token requests","analytics":["AN0454"],"data_components":["DC0088"]},{"channel":"authentication","analytics":["AN0506"],"data_components":["DC0067"]},{"channel":"authentication plugin load or modification events","analytics":["AN1251"],"data_components":["DC0067"]},{"channel":"authorization execute privilege requests","analytics":["AN0977"],"data_components":["DC0021"]},{"channel":"background process persists beyond user logout","analytics":["AN0183"],"data_components":["DC0032"]},{"channel":"base64 -d or osascript invoked on staged file","analytics":["AN0769"],"data_components":["DC0064"]},{"channel":"base64 or curl processes chained within short execution window","analytics":["AN0304"],"data_components":["DC0064"]},{"channel":"binary modified or replaced","analytics":["AN0951"],"data_components":["DC0061"]},{"channel":"boot failure events or SMC validation errors","analytics":["AN0476"],"data_components":["DC0004"]},{"channel":"chmod command with arguments including '+s', 'u+s', or numeric values 4000–6777","analytics":["AN0308"],"data_components":["DC0064"]},{"channel":"code signature/memory protection","analytics":["AN0921"],"data_components":["DC0034"]},{"channel":"com.apple.accountsd, com.apple.opendirectoryd","analytics":["AN0267"],"data_components":["DC0010"]},{"channel":"com.apple.diskarbitration","analytics":["AN0249"],"data_components":["DC0042"]},{"channel":"com.apple.firmwareupdater activity or update-firmware binary invoked","analytics":["AN0476"],"data_components":["DC0032"]},{"channel":"com.apple.mail.* exec.*","analytics":["AN0149"],"data_components":["DC0032"]},{"channel":"com.apple.network","analytics":["AN0598","AN1256"],"data_components":["DC0078"]},{"channel":"com.apple.securityd, com.apple.tccd","analytics":["AN0689"],"data_components":["DC0021"]},{"channel":"command execution triggered by emond (e.g., shell, curl, python)","analytics":["AN1534"],"data_components":["DC0064"]},{"channel":"command includes dscl . delete or sysadminctl --deleteUser","analytics":["AN0336"],"data_components":["DC0064"]},{"channel":"connection attempts","analytics":["AN0032"],"data_components":["DC0082"]},{"channel":"connection open","analytics":["AN0167"],"data_components":["DC0082"]},{"channel":"create/modify dylib files in monitored directories","analytics":["AN0435"],"data_components":["DC0039"]},{"channel":"create/modify dylib in monitored directories","analytics":["AN1210"],"data_components":["DC0061"]},{"channel":"create: New files in /tmp or ~/Library/Application Support/* with executable or script extensions","analytics":["AN0964"],"data_components":["DC0039"]},{"channel":"creation of ~/.vscode-cli/code_tunnel.json","analytics":["AN0377"],"data_components":["DC0039"]},{"channel":"creation or loading of new launchd services","analytics":["AN0736"],"data_components":["DC0060"]},{"channel":"csrutil disable","analytics":["AN1447"],"data_components":["DC0064"]},{"channel":"curl|osascript.*open location","analytics":["AN0149"],"data_components":["DC0085"]},{"channel":"defaults read -g AppleLocale or systemsetup -gettimezone","analytics":["AN1563"],"data_components":["DC0064"]},{"channel":"defaults read -g AppleLocale, systemsetup -gettimezone","analytics":["AN0121"],"data_components":["DC0064"]},{"channel":"defaults write com.apple.system.logging or logd manipulation","analytics":["AN0669"],"data_components":["DC0064"]},{"channel":"delay/sleep library usage in user context","analytics":["AN1050"],"data_components":["DC0016"]},{"channel":"diskutil eraseDisk / asr restore with destructive flags","analytics":["AN0386"],"data_components":["DC0064"]},{"channel":"diskutil eraseDisk/zeroDisk or asr restore with destructive flags","analytics":["AN0884"],"data_components":["DC0064"]},{"channel":"diskutil partitionDisk or eraseVolume with partition scheme modifications","analytics":["AN0829"],"data_components":["DC0064"]},{"channel":"dns-sd, mDNSResponder, socket activity","analytics":["AN1059"],"data_components":["DC0085"]},{"channel":"dscl -create","analytics":["AN1237"],"data_components":["DC0064"]},{"channel":"dscl . -create","analytics":["AN1606"],"data_components":["DC0064"]},{"channel":"dsconfigad or dscl with create or append options for AD-bound users","analytics":["AN0008"],"data_components":["DC0064"]},{"channel":"dyld/unified log entries indicating image load from non-system paths","analytics":["AN0054"],"data_components":["DC0016"]},{"channel":"dynamic loading of sleep-related functions or sandbox detection libraries","analytics":["AN0129"],"data_components":["DC0016"]},{"channel":"encrypted outbound traffic carrying unexpected application data","analytics":["AN1485"],"data_components":["DC0085"]},{"channel":"eventMessage = 'open', 'sendto', 'connect'","analytics":["AN0990"],"data_components":["DC0085"]},{"channel":"eventMessage = 'promiscuous'","analytics":["AN0877"],"data_components":["DC0085"]},{"channel":"eventMessage CONTAINS 'screensharingd' or 'AuthorizationRefCreate'","analytics":["AN0752"],"data_components":["DC0067"]},{"channel":"exec /usr/bin/pwpolicy","analytics":["AN0457"],"data_components":["DC0032"]},{"channel":"exec events where web process starts a shell/tooling","analytics":["AN0221"],"data_components":["DC0032"]},{"channel":"exec logs","analytics":["AN0042","AN0196","AN0726","AN1545","AN2032"],"data_components":["DC0032"]},{"channel":"exec of binary with setuid/setgid and EUID != UID","analytics":["AN0308"],"data_components":["DC0034"]},{"channel":"exec of osascript, bash, curl with suspicious parameters","analytics":["AN0228"],"data_components":["DC0032"]},{"channel":"exec or spawn calls to proxy tools or torrent clients","analytics":["AN0082"],"data_components":["DC0032"]},{"channel":"exec or spawn of 'system_profiler', 'ioreg', 'kextstat', 'sysctl', or calls to sysctl API","analytics":["AN0480"],"data_components":["DC0032"]},{"channel":"exec or sudo usage with NOPASSWD context or echo modifying sudoers","analytics":["AN0143"],"data_components":["DC0064"]},{"channel":"exec rm -rf|dd if=/dev|srm|file unlink","analytics":["AN0413"],"data_components":["DC0040"]},{"channel":"exec srm|exec openssl|exec gpg","analytics":["AN0604"],"data_components":["DC0032"]},{"channel":"exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers","analytics":["AN1450"],"data_components":["DC0032"]},{"channel":"exec: Execution of defaults, plutil, or common editors (vim/nano) targeting plist files","analytics":["AN0306"],"data_components":["DC0032"]},{"channel":"exec: Execution of kextstat, kextfind, or ioreg targeting driver information","analytics":["AN1597"],"data_components":["DC0032"]},{"channel":"exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers.","analytics":["AN0844"],"data_components":["DC0032"]},{"channel":"exec: Invocation of /usr/bin/defaults write or /usr/bin/plutil modifying plist keys","analytics":["AN0306"],"data_components":["DC0064"]},{"channel":"exec: ParentImage in (Terminal, iTerm2) AND Image in (/bin/zsh,/bin/bash,/usr/bin/python*) AND CommandLine matches '(curl|wget).*(\\||\\|\\s*sh|bash)|base64 -D|python -c'","analytics":["AN0964"],"data_components":["DC0032"]},{"channel":"execution of 'security', 'cat', or 'grep' commands accessing credential storage","analytics":["AN1155"],"data_components":["DC0064"]},{"channel":"execution of /sbin/emond with child processes launched","analytics":["AN1534"],"data_components":["DC0032"]},{"channel":"execution of Office binaries with network activity","analytics":["AN1513"],"data_components":["DC0032"]},{"channel":"execution of curl, git, or Office processes with network connections","analytics":["AN0897"],"data_components":["DC0032"]},{"channel":"execution of curl, osascript, or unexpected Office processes","analytics":["AN0789"],"data_components":["DC0032"]},{"channel":"execution of curl, rclone, or Office apps invoking network sessions","analytics":["AN1573"],"data_components":["DC0032"]},{"channel":"execution of launchctl load/unload/start commands","analytics":["AN0736"],"data_components":["DC0064"]},{"channel":"execution of memory inspection tools (lldb, gdb, osqueryi)","analytics":["AN0156"],"data_components":["DC0032"]},{"channel":"execution of modified binary without valid signature","analytics":["AN0951"],"data_components":["DC0032"]},{"channel":"execution of osascript, curl, or unexpected automation","analytics":["AN0438"],"data_components":["DC0032"]},{"channel":"execution of process with DYLD_INSERT_LIBRARIES set","analytics":["AN1210"],"data_components":["DC0032"]},{"channel":"execution of security or osascript","analytics":["AN1112","AN1200"],"data_components":["DC0032"]},{"channel":"execution of security, sqlite3, or unauthorized binaries","analytics":["AN0107"],"data_components":["DC0032"]},{"channel":"execution of security-agent detection or enumeration commands","analytics":["AN0050"],"data_components":["DC0064"]},{"channel":"execution of system_profiler, ioreg, kextstat with argument patterns related to VM/sandbox checks","analytics":["AN0129"],"data_components":["DC0032"]},{"channel":"execve or dylib load from memory without backing file","analytics":["AN0840"],"data_components":["DC0032"]},{"channel":"execve: Helper tools invoked through XPC executing unexpected binaries","analytics":["AN0948"],"data_components":["DC0032"]},{"channel":"extended attribute write or modification","analytics":["AN1136"],"data_components":["DC0059"]},{"channel":"file create or modify in /etc/emond.d/rules or /private/var/db/emondClients","analytics":["AN1534"],"data_components":["DC0039"]},{"channel":"file creation in AV exclusion directories","analytics":["AN0141"],"data_components":["DC0039"]},{"channel":"file encrypted|new file with .encrypted extension|disk write burst","analytics":["AN0604"],"data_components":["DC0061"]},{"channel":"file events","analytics":["AN0042","AN0196","AN0726"],"data_components":["DC0039","DC0055"]},{"channel":"file read of sensitive directories","analytics":["AN0438","AN0789","AN1573"],"data_components":["DC0055"]},{"channel":"file write","analytics":["AN0057"],"data_components":["DC0039"]},{"channel":"file write/create","analytics":["AN0167"],"data_components":["DC0039"]},{"channel":"file writes","analytics":["AN1300"],"data_components":["DC0061"]},{"channel":"filesystem and process events","analytics":["AN1147"],"data_components":["DC0055"]},{"channel":"filesystem events","analytics":["AN0784"],"data_components":["DC0059"]},{"channel":"flock|NSDistributedLock|FileHandle.*lockForWriting","analytics":["AN0374"],"data_components":["DC0021"]},{"channel":"forwarded encrypted traffic","analytics":["AN1022"],"data_components":["DC0078"]},{"channel":"g_CiOptions modification or SIP state change","analytics":["AN1447"],"data_components":["DC0063"]},{"channel":"grep/cat on files matching credential patterns","analytics":["AN0858"],"data_components":["DC0064"]},{"channel":"httpd spawning bash, zsh, python, or osascript","analytics":["AN1110"],"data_components":["DC0032"]},{"channel":"installer or system_installd 'PackageKit: install succeeded/failed' with non-notarized or unknown signer","analytics":["AN1482"],"data_components":["DC0059"]},{"channel":"kextload execution from Terminal or suspicious paths","analytics":["AN1244"],"data_components":["DC0064"]},{"channel":"launch and dylib load","analytics":["AN1467"],"data_components":["DC0016"]},{"channel":"launch of Terminal.app or shell with non-standard environment setup","analytics":["AN0060"],"data_components":["DC0032"]},{"channel":"launch of bash/zsh/python/osascript targeting key file locations","analytics":["AN1518"],"data_components":["DC0032"]},{"channel":"launch of remote desktop app or helper binary","analytics":["AN0716"],"data_components":["DC0032"]},{"channel":"launchctl activity and process creation","analytics":["AN0743"],"data_components":["DC0032"]},{"channel":"launchctl disable or bootout calls","analytics":["AN0063"],"data_components":["DC0041"]},{"channel":"launchctl load or boot-time plist registration","analytics":["AN1208"],"data_components":["DC0064"]},{"channel":"launchctl load/unload or plist file modification","analytics":["AN1577"],"data_components":["DC0064"]},{"channel":"launchctl spawning new processes","analytics":["AN0736"],"data_components":["DC0032"]},{"channel":"launchctl unload, kill, or pkill commands affecting daemons or background services","analytics":["AN0047"],"data_components":["DC0064"]},{"channel":"launchd loading new LaunchDaemon or changes to existing daemon configuration","analytics":["AN1126"],"data_components":["DC0060"]},{"channel":"launchd or cron spawning mining binaries","analytics":["AN1491"],"data_components":["DC0032"]},{"channel":"launchd or osascript spawns process with delay command","analytics":["AN1050"],"data_components":["DC0032"]},{"channel":"launchd services binding to non-standard ports","analytics":["AN0635"],"data_components":["DC0032"]},{"channel":"launchd spawning processes tied to new or modified LaunchDaemon .plist entries","analytics":["AN1126"],"data_components":["DC0032"]},{"channel":"launchservices events for misleading extensions","analytics":["AN0632"],"data_components":["DC0032"]},{"channel":"launchservices or loginwindow events","analytics":["AN1197"],"data_components":["DC0032"]},{"channel":"loading of unexpected dylibs compared to historical baselines","analytics":["AN1210"],"data_components":["DC0016"]},{"channel":"log","analytics":["AN0313"],"data_components":["DC0029"]},{"channel":"log collect --predicate","analytics":["AN1042"],"data_components":["DC0032"]},{"channel":"log collect from launchd and process start","analytics":["AN0985"],"data_components":["DC0034"]},{"channel":"log messages related to disk enumeration context or Terminal session","analytics":["AN0538"],"data_components":["DC0064"]},{"channel":"log show --predicate 'eventMessage contains \"Authentication\"'","analytics":["AN0592"],"data_components":["DC0002"]},{"channel":"log show --predicate 'process == <utility>'","analytics":["AN1454"],"data_components":["DC0064"]},{"channel":"log stream","analytics":["AN0115","AN0239","AN0280","AN0739","AN1218","AN1227"],"data_components":["DC0064"]},{"channel":"log stream 'eventMessage contains \"dns_request\"'","analytics":["AN1123"],"data_components":["DC0078"]},{"channel":"log stream 'eventMessage contains pubsub or broker'","analytics":["AN0004"],"data_components":["DC0032"]},{"channel":"log stream (subsystem: com.apple.system.networking)","analytics":["AN0369"],"data_components":["DC0085"]},{"channel":"log stream - file provider subsystem","analytics":["AN1415"],"data_components":["DC0055"]},{"channel":"log stream - file subsystem","analytics":["AN0425"],"data_components":["DC0055"]},{"channel":"log stream --info --predicate 'eventMessage CONTAINS \"exec\"'","analytics":["AN1430"],"data_components":["DC0032"]},{"channel":"log stream --info --predicate 'subsystem == \"com.apple.cfprefsd\"'","analytics":["AN0102"],"data_components":["DC0032"]},{"channel":"log stream --predicate","analytics":["AN0077","AN1171","AN1590","AN1628"],"data_components":["DC0064"]},{"channel":"log stream --predicate 'eventMessage contains \"USBMSC\"'","analytics":["AN1412"],"data_components":["DC0042"]},{"channel":"log stream --predicate 'eventMessage contains \"exec\"'","analytics":["AN1082"],"data_components":["DC0032"]},{"channel":"log stream --predicate 'eventMessage contains \"loginwindow\" or \"pfctl\"'","analytics":["AN0135"],"data_components":["DC0064"]},{"channel":"log stream --predicate 'eventMessage contains \"python\"'","analytics":["AN0173"],"data_components":["DC0029"]},{"channel":"log stream --predicate 'eventMessage contains \"wscript\" OR \"vbs\"'","analytics":["AN0210"],"data_components":["DC0029"]},{"channel":"log stream --predicate 'processImagePath CONTAINS \"curl\" OR \"osascript\"'","analytics":["AN0381"],"data_components":["DC0032"]},{"channel":"log stream --predicate 'processImagePath contains \"zip\" OR \"base64\"'","analytics":["AN1066"],"data_components":["DC0064"]},{"channel":"log stream cleared or truncated","analytics":["AN0522"],"data_components":["DC0038"]},{"channel":"log stream network activity","analytics":["AN1391"],"data_components":["DC0082"]},{"channel":"log stream process subsystem","analytics":["AN1391"],"data_components":["DC0032"]},{"channel":"log stream with predicate 'eventMessage CONTAINS \"osascript\"'","analytics":["AN0734"],"data_components":["DC0029"]},{"channel":"logMessage contains pbpaste or osascript","analytics":["AN0533"],"data_components":["DC0032"]},{"channel":"logd:file write","analytics":["AN0601"],"data_components":["DC0039"]},{"channel":"loginwindow or desktopservices modified settings or files","analytics":["AN0231"],"data_components":["DC0061"]},{"channel":"loginwindow or sshd","analytics":["AN1139"],"data_components":["DC0088"]},{"channel":"loginwindow or sshd events with external IP","analytics":["AN1624"],"data_components":["DC0088"]},{"channel":"loginwindow or sshd successful login events","analytics":["AN1346"],"data_components":["DC0067"]},{"channel":"loginwindow or tccd-related entries","analytics":["AN0682"],"data_components":["DC0032"]},{"channel":"loginwindow, sshd","analytics":["AN1545"],"data_components":["DC0088"]},{"channel":"looking for file access to scripts with abnormal encoding patterns","analytics":["AN2065"],"data_components":["DC0055"]},{"channel":"memory mapping","analytics":["AN0239"],"data_components":["DC0020"]},{"channel":"modification to /var/db/dslocal/nodes/Default/users/","analytics":["AN1237","AN1606"],"data_components":["DC0061"]},{"channel":"mounted|appeared|DA: disk* attached","analytics":["AN0187"],"data_components":["DC0042"]},{"channel":"network","analytics":["AN1115"],"data_components":["DC0082"]},{"channel":"network connection events","analytics":["AN0333","AN2032"],"data_components":["DC0082"]},{"channel":"network flow","analytics":["AN0146"],"data_components":["DC0085"]},{"channel":"network sessions initiated by remote desktop apps","analytics":["AN0716"],"data_components":["DC0082"]},{"channel":"network stack resource exhaustion, tcp_accept queue overflow, repeated resets","analytics":["AN1014"],"data_components":["DC0018"]},{"channel":"network, socket, and http logs","analytics":["AN0566"],"data_components":["DC0085"]},{"channel":"networkd or com.apple.network","analytics":["AN1120"],"data_components":["DC0078"]},{"channel":"networkd or socket","analytics":["AN1383"],"data_components":["DC0082"]},{"channel":"new DHCP configuration with anomalous DNS or router values","analytics":["AN1292"],"data_components":["DC0038"]},{"channel":"nohup, disown, or osascript execution patterns","analytics":["AN0183"],"data_components":["DC0064"]},{"channel":"non-shell process tree accessing bash history","analytics":["AN1086"],"data_components":["DC0034"]},{"channel":"open URL|clicked link|LSQuarantineAttach","analytics":["AN0180"],"data_components":["DC0085"]},{"channel":"open/read access to private key files (id_rsa, *.pem, *.p12)","analytics":["AN1518"],"data_components":["DC0055"]},{"channel":"open/read of *.plist or .env files","analytics":["AN0858"],"data_components":["DC0055"]},{"channel":"open: Access to /var/log/system.log or related security event logs","analytics":["AN0707"],"data_components":["DC0055"]},{"channel":"opendirectoryd crashes or abnormal authentication errors","analytics":["AN0495"],"data_components":["DC0038"]},{"channel":"opened document|clicked link|EXC_BAD_ACCESS|abort|LSQuarantine","analytics":["AN1316"],"data_components":["DC0038"]},{"channel":"osascript or AppleScript invocation modifying UI","analytics":["AN0231"],"data_components":["DC0029"]},{"channel":"osascript, AppleScript, or Python execution triggered immediately after HID connection","analytics":["AN1569"],"data_components":["DC0029"]},{"channel":"outbound HTTPS connections to cloud storage APIs","analytics":["AN1573"],"data_components":["DC0085"]},{"channel":"outbound HTTPS connections to code repository APIs","analytics":["AN0897"],"data_components":["DC0085"]},{"channel":"outbound TCP/UDP traffic over unexpected port","analytics":["AN0635"],"data_components":["DC0078"]},{"channel":"outbound TLS connections to cloud storage providers","analytics":["AN1513"],"data_components":["DC0085"]},{"channel":"pfctl -d, socketfilterfw --setglobalstate off, or modifications to com.apple.alf","analytics":["AN0408"],"data_components":["DC0064"]},{"channel":"pkginstalld/softwareupdated/Homebrew install transactions","analytics":["AN0864"],"data_components":["DC0059"]},{"channel":"process","analytics":["AN0146","AN0357","AN0394","AN0468","AN0561","AN0966","AN1017","AN1282","AN1439","AN1585"],"data_components":["DC0032","DC0034"]},{"channel":"process 'crashed'|'EXC_BAD_ACCESS' for sshd, screensharingd, httpd; launchd restarts of these daemons.","analytics":["AN0330"],"data_components":["DC0038"]},{"channel":"process + network activity","analytics":["AN1191"],"data_components":["DC0085"]},{"channel":"process + network metrics correlation for bandwidth saturation","analytics":["AN0082"],"data_components":["DC0085"]},{"channel":"process = 'ssh' OR eventMessage CONTAINS 'ssh'","analytics":["AN1639"],"data_components":["DC0085"]},{"channel":"process = 'sshd'","analytics":["AN1639"],"data_components":["DC0088"]},{"channel":"process activity, exec events","analytics":["AN1383"],"data_components":["DC0032"]},{"channel":"process and file events via log stream","analytics":["AN0294"],"data_components":["DC0032"]},{"channel":"process and signing chain events","analytics":["AN0625"],"data_components":["DC0032"]},{"channel":"process calling security find-certificate, export, or import","analytics":["AN0673"],"data_components":["DC0064"]},{"channel":"process command line contains base64, -enc, openssl enc -base64","analytics":["AN0347"],"data_components":["DC0032"]},{"channel":"process crash, abort, code signing violations","analytics":["AN0799"],"data_components":["DC0038"]},{"channel":"process created with repeated ICMP or UDP flood behavior","analytics":["AN0971"],"data_components":["DC0032"]},{"channel":"process event","analytics":["AN1614"],"data_components":["DC0032"]},{"channel":"process events","analytics":["AN0659","AN0813","AN1027"],"data_components":["DC0032"]},{"channel":"process exec","analytics":["AN1355"],"data_components":["DC0032"]},{"channel":"process exec events of systemsetup, date, ioreg with command_line parameters indicating time discovery","analytics":["AN0432"],"data_components":["DC0032"]},{"channel":"process execution events for chmod, chown, chflags with parameter analysis and target path examination","analytics":["AN0999"],"data_components":["DC0032"]},{"channel":"process execution events for chmod, chown, chflags with unusual parameters or targets","analytics":["AN0836"],"data_components":["DC0032"]},{"channel":"process execution events for discovery utilities (system_profiler, sw_vers, dscl, networksetup) with command-line parameter analysis","analytics":["AN1307"],"data_components":["DC0032"]},{"channel":"process execution events for system discovery utilities (system_profiler, sysctl, networksetup, ioreg) with parameter analysis","analytics":["AN1553"],"data_components":["DC0032"]},{"channel":"process execution events with dylib load activity","analytics":["AN0435"],"data_components":["DC0016"]},{"channel":"process execution of ssh with -L/-R forwarding flags","analytics":["AN1485"],"data_components":["DC0032"]},{"channel":"process launch","analytics":["AN0097","AN0260"],"data_components":["DC0032"]},{"channel":"process launch of diskutil or system_profiler with SPStorageDataType","analytics":["AN0538"],"data_components":["DC0032"]},{"channel":"process logs","analytics":["AN0924"],"data_components":["DC0032"]},{"channel":"process writes or modifies files in excluded paths","analytics":["AN0141"],"data_components":["DC0032"]},{"channel":"process, network","analytics":["AN1601"],"data_components":["DC0085"]},{"channel":"process, socket, and DNS logs","analytics":["AN1022"],"data_components":["DC0032"]},{"channel":"process.*exit.*code","analytics":["AN0374","AN0413"],"data_components":["DC0033"]},{"channel":"process: at, job runner","analytics":["AN0945"],"data_components":["DC0064"]},{"channel":"process: code or jetbrains-gateway launching with --tunnel or --remote","analytics":["AN0377"],"data_components":["DC0032"]},{"channel":"process: crontab edits, launch of cron job","analytics":["AN0806"],"data_components":["DC0001"]},{"channel":"process: exec","analytics":["AN0981","AN1115"],"data_components":["DC0032"]},{"channel":"process: exec + filewrite: ~/.ssh/authorized_keys","analytics":["AN0351"],"data_components":["DC0032"]},{"channel":"process: spawn, exec","analytics":["AN1164"],"data_components":["DC0032"]},{"channel":"process::exec","analytics":["AN0068"],"data_components":["DC0032"]},{"channel":"process:exec","analytics":["AN0319"],"data_components":["DC0032"]},{"channel":"process:exec and kext load events","analytics":["AN1421"],"data_components":["DC0032"]},{"channel":"process:launch","analytics":["AN0509"],"data_components":["DC0032"]},{"channel":"process:spawn","analytics":["AN1072","AN1530"],"data_components":["DC0032"]},{"channel":"process:spawn, process:exec","analytics":["AN1396"],"data_components":["DC0064"]},{"channel":"process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary","analytics":["AN0500"],"data_components":["DC0032"]},{"channel":"process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder}","analytics":["AN0820"],"data_components":["DC0032"]},{"channel":"process_name IN (\"VBoxManage\", \"prlctl\") AND command CONTAINS (\"list\", \"show\")","analytics":["AN0575"],"data_components":["DC0032"]},{"channel":"profiles install -type=configuration","analytics":["AN0124"],"data_components":["DC0064"]},{"channel":"ptrace or task_for_pid","analytics":["AN0156"],"data_components":["DC0035"]},{"channel":"ptrace: Processes invoking ptrace with PTRACE_TRACEME flag","analytics":["AN1047"],"data_components":["DC0021"]},{"channel":"pwpolicy|PasswordPolicy","analytics":["AN0457"],"data_components":["DC0064"]},{"channel":"quarantine or AV-related subsystem","analytics":["AN0542"],"data_components":["DC0038"]},{"channel":"read access to ~/Library/Keychains or history files by terminal processes","analytics":["AN1155"],"data_components":["DC0055"]},{"channel":"read access to ~/Library/Keychains/login.keychain-db","analytics":["AN1112"],"data_components":["DC0055"]},{"channel":"read of user document directories","analytics":["AN0897"],"data_components":["DC0055"]},{"channel":"read/write of user documents prior to upload","analytics":["AN1513"],"data_components":["DC0055"]},{"channel":"read: File access to /System/Library/Extensions/ or related kernel extension paths","analytics":["AN1597"],"data_components":["DC0055"]},{"channel":"replace existing dylibs","analytics":["AN0435"],"data_components":["DC0061"]},{"channel":"rule definitions written to emond rule plists","analytics":["AN1534"],"data_components":["DC0061"]},{"channel":"security OR injection attempts into 1Password OR LastPass","analytics":["AN1643"],"data_components":["DC0032"]},{"channel":"shutdown -h now or reboot","analytics":["AN1540"],"data_components":["DC0032"]},{"channel":"softwareupdated/homebrew/install logs, pkginstalld events","analytics":["AN0023"],"data_components":["DC0059"]},{"channel":"spctl --master-disable, csrutil disable, or defaults write to disable Gatekeeper","analytics":["AN0888"],"data_components":["DC0064"]},{"channel":"subsystem: com.apple.WebKit or com.apple.WebKit.Networking","analytics":["AN1409"],"data_components":["DC0085"]},{"channel":"subsystem: com.apple.network","analytics":["AN0160"],"data_components":["DC0085"]},{"channel":"subsystem:com.apple.Terminal","analytics":["AN0256"],"data_components":["DC0064"]},{"channel":"subsystem:syspolicyd","analytics":["AN0090"],"data_components":["DC0059"]},{"channel":"subsystem=com.apple.Security or com.apple.applescript","analytics":["AN1442"],"data_components":["DC0029"]},{"channel":"subsystem=com.apple.TCC","analytics":["AN0245","AN0284"],"data_components":["DC0034"]},{"channel":"subsystem=com.apple.WebKit","analytics":["AN1322"],"data_components":["DC0085"]},{"channel":"subsystem=com.apple.kextd","analytics":["AN1063"],"data_components":["DC0016"]},{"channel":"subsystem=com.apple.launchservices","analytics":["AN0326"],"data_components":["DC0041"]},{"channel":"subsystem=com.apple.lsd","analytics":["AN1462"],"data_components":["DC0059"]},{"channel":"subsystem=com.apple.process","analytics":["AN0013"],"data_components":["DC0034"]},{"channel":"subsystem=com.apple.security, library=libsystem_kernel.dylib","analytics":["AN1401"],"data_components":["DC0035"]},{"channel":"subsystem=launchservices","analytics":["AN0533"],"data_components":["DC0029"]},{"channel":"successful sudo or authentication for account not normally associated with admin actions","analytics":["AN0336"],"data_components":["DC0002"]},{"channel":"sudden burst in outgoing packets from same PID","analytics":["AN0971"],"data_components":["DC0078"]},{"channel":"suspicious dlopen/dlsym usage in non-development processes","analytics":["AN0840"],"data_components":["DC0016"]},{"channel":"tcp/udp","analytics":["AN0639"],"data_components":["DC0078"]},{"channel":"vm_read, task_for_pid, or file open to cookie databases","analytics":["AN1404"],"data_components":["DC0035"]},{"channel":"write","analytics":["AN0766"],"data_components":["DC0061"]},{"channel":"write of plist files in /Library/LaunchAgents or /Library/LaunchDaemons","analytics":["AN0736"],"data_components":["DC0061"]},{"channel":"write: File modification to com.apple.PowerManagement.plist or related system preference files","analytics":["AN1176"],"data_components":["DC0061"]},{"channel":"write: File modifications to *.plist within LaunchAgents, LaunchDaemons, Application Support, or Preferences directories","analytics":["AN0306"],"data_components":["DC0061"]},{"channel":"xattr -d com.apple.quarantine or similar attribute removal commands","analytics":["AN0800"],"data_components":["DC0059"]},{"channel":"xattr -d com.apple.quarantine or similar removal commands","analytics":["AN1248"],"data_components":["DC0064"]},{"channel":"xattr utility execution with -w or -p flags","analytics":["AN1136"],"data_components":["DC0064"]},{"channel":"~/Library/Application Support/Google/Chrome/*/Login Data OR ~/Library/Application Support/Firefox/*/logins.json","analytics":["AN0107"],"data_components":["DC0055"]}],"data_components":["DC0001","DC0002","DC0004","DC0005","DC0007","DC0010","DC0013","DC0016","DC0018","DC0020","DC0021","DC0029","DC0032","DC0033","DC0034","DC0035","DC0038","DC0039","DC0040","DC0041","DC0042","DC0046","DC0048","DC0055","DC0059","DC0060","DC0061","DC0063","DC0064","DC0067","DC0074","DC0078","DC0082","DC0085","DC0088"],"analytics":["AN0004","AN0008","AN0011","AN0013","AN0023","AN0026","AN0032","AN0036","AN0039","AN0042","AN0047","AN0050","AN0054","AN0057","AN0060","AN0063","AN0068","AN0070","AN0073","AN0077","AN0082","AN0090","AN0093","AN0097","AN0102","AN0107","AN0111","AN0115","AN0121","AN0124","AN0129","AN0135","AN0141","AN0143","AN0146","AN0149","AN0155","AN0156","AN0160","AN0164","AN0167","AN0173","AN0180","AN0183","AN0187","AN0190","AN0196","AN0206","AN0210","AN0214","AN0218","AN0221","AN0228","AN0231","AN0239","AN0242","AN0245","AN0249","AN0252","AN0256","AN0260","AN0267","AN0273","AN0280","AN0284","AN0289","AN0294","AN0300","AN0304","AN0306","AN0308","AN0313","AN0319","AN0322","AN0326","AN0330","AN0333","AN0336","AN0340","AN0344","AN0347","AN0349","AN0351","AN0357","AN0362","AN0365","AN0369","AN0374","AN0377","AN0381","AN0386","AN0391","AN0394","AN0398","AN0402","AN0408","AN0413","AN0425","AN0432","AN0435","AN0438","AN0448","AN0454","AN0457","AN0464","AN0468","AN0476","AN0480","AN0486","AN0491","AN0495","AN0500","AN0506","AN0509","AN0515","AN0518","AN0522","AN0533","AN0538","AN0542","AN0547","AN0552","AN0557","AN0561","AN0566","AN0570","AN0575","AN0586","AN0592","AN0598","AN0601","AN0604","AN0607","AN0611","AN0618","AN0621","AN0625","AN0632","AN0635","AN0639","AN0644","AN0650","AN0653","AN0657","AN0659","AN0664","AN0669","AN0673","AN0678","AN0682","AN0685","AN0689","AN0700","AN0704","AN0707","AN0711","AN0716","AN0721","AN0726","AN0730","AN0734","AN0736","AN0739","AN0743","AN0749","AN0752","AN0761","AN0766","AN0769","AN0776","AN0780","AN0784","AN0789","AN0794","AN0799","AN0800","AN0806","AN0813","AN0820","AN0825","AN0829","AN0833","AN0836","AN0840","AN0844","AN0848","AN0852","AN0858","AN0864","AN0867","AN0870","AN0874","AN0877","AN0884","AN0888","AN0897","AN0911","AN0918","AN0921","AN0924","AN0938","AN0945","AN0948","AN0951","AN0964","AN0966","AN0971","AN0977","AN0981","AN0985","AN0990","AN0994","AN0997","AN0999","AN1003","AN1006","AN1011","AN1014","AN1017","AN1022","AN1027","AN1037","AN1039","AN1042","AN1047","AN1050","AN1059","AN1063","AN1066","AN1072","AN1082","AN1086","AN1093","AN1099","AN1102","AN1110","AN1111","AN1112","AN1115","AN1120","AN1123","AN1126","AN1136","AN1139","AN1142","AN1147","AN1150","AN1155","AN1163","AN1164","AN1167","AN1171","AN1176","AN1180","AN1184","AN1191","AN1197","AN1200","AN1204","AN1208","AN1210","AN1215","AN1218","AN1224","AN1227","AN1231","AN1237","AN1244","AN1248","AN1251","AN1256","AN1264","AN1273","AN1278","AN1282","AN1292","AN1296","AN1300","AN1307","AN1311","AN1316","AN1322","AN1327","AN1333","AN1338","AN1346","AN1355","AN1359","AN1363","AN1368","AN1371","AN1378","AN1383","AN1386","AN1391","AN1396","AN1401","AN1404","AN1409","AN1412","AN1415","AN1421","AN1430","AN1439","AN1442","AN1445","AN1447","AN1450","AN1454","AN1460","AN1462","AN1467","AN1474","AN1478","AN1482","AN1485","AN1491","AN1498","AN1509","AN1513","AN1518","AN1523","AN1530","AN1533","AN1534","AN1540","AN1545","AN1550","AN1553","AN1556","AN1563","AN1569","AN1573","AN1577","AN1585","AN1590","AN1597","AN1601","AN1606","AN1609","AN1614","AN1624","AN1628","AN1635","AN1639","AN1643","AN2032","AN2036","AN2040","AN2065"],"techniques":["T1001","T1001.001","T1001.002","T1001.003","T1003","T1005","T1007","T1008","T1010","T1011","T1011.001","T1014","T1016","T1016.001","T1016.002","T1018","T1020","T1021","T1021.004","T1021.005","T1025","T1027","T1027.001","T1027.002","T1027.003","T1027.004","T1027.005","T1027.006","T1027.008","T1027.009","T1027.010","T1027.013","T1027.014","T1027.015","T1027.017","T1027.018","T1029","T1030","T1033","T1036","T1036.001","T1036.002","T1036.003","T1036.004","T1036.005","T1036.006","T1036.008","T1036.009","T1036.012","T1037","T1037.002","T1037.004","T1037.005","T1039","T1040","T1041","T1046","T1048","T1048.001","T1048.002","T1048.003","T1052","T1052.001","T1053","T1053.002","T1053.003","T1055","T1056","T1056.001","T1056.002","T1056.003","T1056.004","T1057","T1059","T1059.002","T1059.004","T1059.005","T1059.006","T1059.007","T1059.011","T1068","T1069","T1069.001","T1069.002","T1070","T1070.003","T1070.004","T1070.006","T1070.007","T1070.008","T1070.009","T1070.010","T1071","T1071.001","T1071.002","T1071.003","T1071.004","T1071.005","T1072","T1074","T1074.001","T1074.002","T1078","T1078.002","T1078.003","T1080","T1082","T1083","T1087","T1087.001","T1087.002","T1090","T1090.001","T1090.002","T1090.003","T1090.004","T1092","T1095","T1098","T1098.004","T1098.007","T1102","T1102.001","T1102.002","T1102.003","T1104","T1105","T1106","T1110","T1110.001","T1110.002","T1110.003","T1110.004","T1111","T1113","T1114","T1114.003","T1115","T1119","T1120","T1123","T1124","T1125","T1129","T1132","T1132.001","T1133","T1135","T1136","T1136.001","T1136.002","T1140","T1176","T1176.001","T1176.002","T1189","T1190","T1195","T1195.001","T1195.002","T1195.003","T1199","T1200","T1201","T1203","T1204","T1204.001","T1204.002","T1204.004","T1204.005","T1205","T1205.001","T1205.002","T1210","T1211","T1212","T1213","T1213.006","T1217","T1218","T1218.015","T1219","T1219.001","T1219.002","T1219.003","T1222","T1222.002","T1480","T1480.001","T1480.002","T1485","T1486","T1489","T1491","T1491.001","T1491.002","T1495","T1496","T1496.001","T1496.002","T1497","T1497.001","T1497.002","T1497.003","T1498.001","T1498.002","T1499","T1499.001","T1499.002","T1499.003","T1499.004","T1505","T1505.003","T1518","T1518.001","T1518.002","T1529","T1531","T1534","T1539","T1542","T1542.002","T1543","T1543.001","T1543.004","T1546","T1546.004","T1546.005","T1546.006","T1546.014","T1546.016","T1547","T1547.006","T1547.007","T1547.015","T1548","T1548.001","T1548.003","T1548.004","T1548.006","T1552","T1552.001","T1552.003","T1552.004","T1553","T1553.001","T1553.002","T1553.004","T1553.006","T1554","T1555","T1555.001","T1555.002","T1555.003","T1555.005","T1556","T1556.003","T1556.006","T1557","T1557.002","T1557.003","T1558","T1558.005","T1559","T1559.003","T1560","T1560.001","T1560.002","T1560.003","T1561","T1561.001","T1561.002","T1563","T1563.001","T1564","T1564.001","T1564.002","T1564.003","T1564.005","T1564.006","T1564.007","T1564.008","T1564.009","T1564.011","T1564.012","T1564.014","T1565","T1565.001","T1565.002","T1565.003","T1566","T1566.001","T1566.002","T1566.003","T1566.004","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1568","T1568.001","T1568.002","T1568.003","T1569","T1569.001","T1570","T1571","T1572","T1573","T1573.001","T1573.002","T1574","T1574.004","T1574.006","T1574.007","T1606","T1606.001","T1614","T1614.001","T1620","T1621","T1622","T1647","T1649","T1652","T1653","T1654","T1657","T1659","T1665","T1667","T1668","T1669","T1673","T1674","T1678","T1680","T1684","T1684.001","T1684.002","T1685","T1685.003","T1685.006","T1686","T1687","T1689","T1690"],"platforms":["macOS"],"kev_cves":["CVE-2007-5659","CVE-2008-0655","CVE-2008-2992","CVE-2009-1862","CVE-2009-3953","CVE-2009-3960","CVE-2009-4324","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2011-2462","CVE-2012-0754","CVE-2012-0767","CVE-2012-1535","CVE-2012-2034","CVE-2012-5054","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0640","CVE-2013-0641","CVE-2013-3346","CVE-2014-0496","CVE-2014-0546","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-3113","CVE-2015-5119","CVE-2015-7645","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1010","CVE-2016-1019","CVE-2016-4117","CVE-2016-4437","CVE-2016-7855","CVE-2017-11292","CVE-2017-11882","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-0296","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-15982","CVE-2018-4878","CVE-2018-4939","CVE-2018-4990","CVE-2018-6789","CVE-2018-7600","CVE-2019-0211","CVE-2019-0604","CVE-2019-0708","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2019-19781","CVE-2019-3396","CVE-2019-3398","CVE-2019-5591","CVE-2020-0069","CVE-2020-0688","CVE-2020-0787","CVE-2020-12812","CVE-2020-1472","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3452","CVE-2020-3580","CVE-2020-5735","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2020-8657","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21017","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22899","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26855","CVE-2021-26857","CVE-2021-26858","CVE-2021-27059","CVE-2021-27065","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-28550","CVE-2021-29256","CVE-2021-30554","CVE-2021-31166","CVE-2021-31207","CVE-2021-3129","CVE-2021-32030","CVE-2021-33739","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-36934","CVE-2021-37415","CVE-2021-37975","CVE-2021-39144","CVE-2021-39226","CVE-2021-4034","CVE-2021-40449","CVE-2021-40539","CVE-2021-40655","CVE-2021-41379","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-44077","CVE-2021-44168","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45046","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-1388","CVE-2022-20699","CVE-2022-20700","CVE-2022-20701","CVE-2022-20703","CVE-2022-20708","CVE-2022-20821","CVE-2022-21919","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22947","CVE-2022-22948","CVE-2022-22954","CVE-2022-22960","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24086","CVE-2022-24521","CVE-2022-24682","CVE-2022-26134","CVE-2022-26138","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-30190","CVE-2022-3038","CVE-2022-3075","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-40684","CVE-2022-41033","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2022-47966","CVE-2023-0386","CVE-2023-0669","CVE-2023-1389","CVE-2023-20109","CVE-2023-20118","CVE-2023-20198","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-2136","CVE-2023-21608","CVE-2023-21674","CVE-2023-21715","CVE-2023-22515","CVE-2023-22518","CVE-2023-22527","CVE-2023-22952","CVE-2023-23397","CVE-2023-2533","CVE-2023-26359","CVE-2023-26360","CVE-2023-26369","CVE-2023-27350","CVE-2023-27524","CVE-2023-27532","CVE-2023-27997","CVE-2023-28229","CVE-2023-28252","CVE-2023-2868","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-32315","CVE-2023-33246","CVE-2023-33538","CVE-2023-34048","CVE-2023-34192","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-39780","CVE-2023-40044","CVE-2023-41179","CVE-2023-42793","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-4966","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-6548","CVE-2023-6549","CVE-2023-7024","CVE-2023-7101","CVE-2024-0769","CVE-2024-11120","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20359","CVE-2024-20399","CVE-2024-20439","CVE-2024-20953","CVE-2024-21413","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-26169","CVE-2024-27198","CVE-2024-27443","CVE-2024-29059","CVE-2024-30051","CVE-2024-34102","CVE-2024-37085","CVE-2024-38080","CVE-2024-38112","CVE-2024-38475","CVE-2024-40890","CVE-2024-40891","CVE-2024-41710","CVE-2024-41713","CVE-2024-42009","CVE-2024-4358","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-48248","CVE-2024-4879","CVE-2024-4885","CVE-2024-49035","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-50603","CVE-2024-5217","CVE-2024-5274","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-55591","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-0411","CVE-2025-0994","CVE-2025-1316","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21480","CVE-2025-21590","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24054","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-24991","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27038","CVE-2025-27363","CVE-2025-2783","CVE-2025-30397","CVE-2025-30400","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-34028","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-48927","CVE-2025-48928","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"macos-endpointsecurity","name":"macos:endpointsecurity","channels":[{"channel":"ES_EVENT_MMAP","analytics":["AN0068"],"data_components":["DC0020"]},{"channel":"ES_EVENT_TYPE_NOTIFY_CONNECT","analytics":["AN0598"],"data_components":["DC0082"]},{"channel":"ES_EVENT_TYPE_NOTIFY_CREATE: path under /Users/*/(Downloads|Desktop|Library/*/Containers|Library/Group Containers) AND extension in SuspiciousExtensions","analytics":["AN0820"],"data_components":["DC0039"]},{"channel":"ES_EVENT_TYPE_NOTIFY_EXEC","analytics":["AN0013","AN0057","AN0090","AN0167","AN0256","AN0326","AN0357","AN0601","AN0639","AN0915","AN0921","AN1120","AN1396","AN1409","AN1462","AN1467"],"data_components":["DC0032"]},{"channel":"ES_EVENT_TYPE_NOTIFY_EXEC, ES_EVENT_TYPE_NOTIFY_MMAP","analytics":["AN1401"],"data_components":["DC0034"]},{"channel":"ES_EVENT_TYPE_NOTIFY_EXEC: Process execution of \"sharing -l\", \"smbutil view\", \"mount_smbfs\"","analytics":["AN0515"],"data_components":["DC0032"]},{"channel":"ES_EVENT_TYPE_NOTIFY_EXEC: arguments contain long, non-standard tokens / custom alphabets","analytics":["AN0929"],"data_components":["DC0032"]},{"channel":"ES_EVENT_TYPE_NOTIFY_KEXTLOAD","analytics":["AN1421"],"data_components":["DC0016"]},{"channel":"ES_EVENT_TYPE_NOTIFY_MMAP","analytics":["AN0915","AN0921"],"data_components":["DC0020"]},{"channel":"ES_EVENT_TYPE_NOTIFY_OPEN","analytics":["AN0915"],"data_components":["DC0035"]},{"channel":"ES_EVENT_TYPE_NOTIFY_OPEN: Open of .dylib/.so in user-writable locations","analytics":["AN0054"],"data_components":["DC0055"]},{"channel":"ES_EVENT_TYPE_NOTIFY_WRITE, targeting .zshrc, .zlogin, .zprofile","analytics":["AN0060"],"data_components":["DC0061"]},{"channel":"es_event_authentication","analytics":["AN1037"],"data_components":["DC0059"]},{"channel":"es_event_exec","analytics":["AN0239"],"data_components":["DC0032"]},{"channel":"es_event_file_rename_t or es_event_file_write_t","analytics":["AN0349"],"data_components":["DC0059"]},{"channel":"es_event_open, es_event_exec","analytics":["AN1311"],"data_components":["DC0055"]},{"channel":"exec","analytics":["AN0023","AN0864"],"data_components":["DC0032"]},{"channel":"exec events","analytics":["AN1601"],"data_components":["DC0032"]},{"channel":"exec: Exec of ffmpeg, avfoundation-based binaries, or custom signed apps accessing camera","analytics":["AN0570"],"data_components":["DC0032"]},{"channel":"exec: Process execution context for loaders calling dlopen/dlsym","analytics":["AN0054"],"data_components":["DC0032"]},{"channel":"open or read syscall to ~/.bash_history","analytics":["AN1086"],"data_components":["DC0055"]},{"channel":"open: Process opens AppleCamera/IOUSB device nodes or AVFoundation frameworks","analytics":["AN0570"],"data_components":["DC0055"]},{"channel":"write, rename","analytics":["AN1482"],"data_components":["DC0061"]}],"data_components":["DC0016","DC0020","DC0032","DC0034","DC0035","DC0039","DC0055","DC0059","DC0061","DC0082"],"analytics":["AN0013","AN0023","AN0054","AN0057","AN0060","AN0068","AN0090","AN0167","AN0239","AN0256","AN0326","AN0349","AN0357","AN0515","AN0570","AN0598","AN0601","AN0639","AN0820","AN0864","AN0915","AN0921","AN0929","AN1037","AN1086","AN1120","AN1311","AN1396","AN1401","AN1409","AN1421","AN1462","AN1467","AN1482","AN1601"],"techniques":["T1027.002","T1027.008","T1027.009","T1027.010","T1027.013","T1027.014","T1027.016","T1027.017","T1029","T1030","T1033","T1036","T1036.001","T1036.002","T1036.003","T1036.004","T1055","T1068","T1102.003","T1104","T1105","T1106","T1114","T1125","T1129","T1132.002","T1135","T1195","T1195.001","T1195.002","T1195.003","T1204.002","T1546.004","T1547.007","T1552.003"],"platforms":["macOS"],"kev_cves":["CVE-2007-5659","CVE-2008-0655","CVE-2008-2992","CVE-2009-1862","CVE-2009-3953","CVE-2009-4324","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2011-2462","CVE-2012-0754","CVE-2012-1535","CVE-2013-0641","CVE-2014-0496","CVE-2014-0546","CVE-2015-3043","CVE-2015-3113","CVE-2015-5119","CVE-2015-7645","CVE-2015-8651","CVE-2016-0984","CVE-2016-1019","CVE-2016-4117","CVE-2017-11292","CVE-2018-15982","CVE-2018-4878","CVE-2018-4990","CVE-2019-0211","CVE-2020-0069","CVE-2020-0688","CVE-2020-0787","CVE-2020-1472","CVE-2020-29574","CVE-2020-8657","CVE-2021-21017","CVE-2021-22900","CVE-2021-28550","CVE-2021-29256","CVE-2021-32030","CVE-2021-33739","CVE-2021-35394","CVE-2021-36934","CVE-2021-4034","CVE-2021-40449","CVE-2021-41379","CVE-2021-44515","CVE-2021-44529","CVE-2022-20708","CVE-2022-21919","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-24521","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-30190","CVE-2022-34713","CVE-2022-37969","CVE-2022-41033","CVE-2022-41073","CVE-2022-41125","CVE-2022-47966","CVE-2023-1389","CVE-2023-20118","CVE-2023-20273","CVE-2023-20867","CVE-2023-21608","CVE-2023-21674","CVE-2023-21715","CVE-2023-22518","CVE-2023-26360","CVE-2023-26369","CVE-2023-27350","CVE-2023-28229","CVE-2023-28252","CVE-2023-2868","CVE-2023-29300","CVE-2023-33538","CVE-2023-34192","CVE-2023-34362","CVE-2023-3519","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38831","CVE-2023-44221","CVE-2023-48788","CVE-2023-6548","CVE-2023-7101","CVE-2024-12686","CVE-2024-12987","CVE-2024-20439","CVE-2024-23692","CVE-2024-27443","CVE-2024-29059","CVE-2024-30051","CVE-2024-37085","CVE-2024-38080","CVE-2024-40890","CVE-2024-40891","CVE-2024-41710","CVE-2024-41713","CVE-2024-42009","CVE-2024-4577","CVE-2024-4885","CVE-2024-49035","CVE-2024-4978","CVE-2024-50603","CVE-2024-53104","CVE-2024-53197","CVE-2024-54085","CVE-2024-55591","CVE-2024-56145","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-0994","CVE-2025-1316","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21480","CVE-2025-21590","CVE-2025-22224","CVE-2025-22225","CVE-2025-24085","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27363","CVE-2025-30400","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-43200","CVE-2025-4632","CVE-2025-47812","CVE-2025-54309"]},{"slug":"auditd-execve","name":"auditd:EXECVE","channels":[{"channel":"/usr/sbin/postfix, /usr/sbin/exim, /usr/sbin/sendmail","analytics":["AN0473"],"data_components":["DC0032"]},{"channel":"EXECVE","analytics":["AN0056","AN1418","AN1638"],"data_components":["DC0032"]},{"channel":"Execution of GUI-related binaries with suppressed window/display flags","analytics":["AN0361"],"data_components":["DC0064"]},{"channel":"Execution of auditctl, systemctl stop auditd, or kill -9 auditd","analytics":["AN0171"],"data_components":["DC0064"]},{"channel":"Execution of chattr to set +i or +a attributes","analytics":["AN1385"],"data_components":["DC0064"]},{"channel":"Execution of dd, shred, or wipe with arguments targeting block devices","analytics":["AN0883"],"data_components":["DC0032"]},{"channel":"Execution of dd, shred, wipe targeting block devices","analytics":["AN0385"],"data_components":["DC0032"]},{"channel":"Execution of dd/sgdisk with arguments writing to sector 0 or partition table","analytics":["AN0828"],"data_components":["DC0032"]},{"channel":"Execution of gsettings set org.gnome.login-screen disable-user-list true","analytics":["AN1002"],"data_components":["DC0064"]},{"channel":"Execution of ssh/scp/sftp without corresponding authentication log","analytics":["AN0710"],"data_components":["DC0032"]},{"channel":"None","analytics":["AN0505","AN1062"],"data_components":["DC0032"]},{"channel":"Process execution of update-ca-certificates or openssl with suspicious arguments","analytics":["AN1247"],"data_components":["DC0064"]},{"channel":"Process execution via .desktop Exec path from /etc/xdg/autostart or ~/.config/autostart","analytics":["AN1096"],"data_components":["DC0032"]},{"channel":"Use of mv or cp to rename files with '.' prefix","analytics":["AN0092"],"data_components":["DC0064"]},{"channel":"cat|less|grep accessing .bash_history from a non-shell process","analytics":["AN1085"],"data_components":["DC0032"]},{"channel":"command line arguments containing lsblk, fdisk, parted","analytics":["AN0537"],"data_components":["DC0064"]},{"channel":"curl -T, rclone copy","analytics":["AN1572"],"data_components":["DC0064"]},{"channel":"curl -X POST, wget --post-data","analytics":["AN0437"],"data_components":["DC0064"]},{"channel":"curl -d, wget --post-data","analytics":["AN0788"],"data_components":["DC0064"]},{"channel":"curl or wget with POST/PUT options","analytics":["AN1512"],"data_components":["DC0064"]},{"channel":"exec: Execution of dd, efibootmgr, or flashrom modifying firmware/boot partitions","analytics":["AN0775"],"data_components":["DC0064"]},{"channel":"execution of setfattr or getfattr commands","analytics":["AN1135"],"data_components":["DC0064"]},{"channel":"execution of systemctl with subcommands start, stop, enable, disable","analytics":["AN0200"],"data_components":["DC0064"]},{"channel":"execution of unexpected binaries during user shell startup","analytics":["AN0059"],"data_components":["DC0032"]},{"channel":"execve","analytics":["AN0272","AN0560","AN0950","AN1016","AN1199","AN1281","AN1326","AN1517","AN1584"],"data_components":["DC0032"]},{"channel":"execve of curl,wget,bash,sh,python with piped or remote content","analytics":["AN2037"],"data_components":["DC0064"]},{"channel":"execve of script/interpreter (bash, python, node) with suspicious encoded or non-printable content","analytics":["AN2064"],"data_components":["DC0064"]},{"channel":"execve, kill, ptrace, insmod, rmmod targeting security processes","analytics":["AN2039"],"data_components":["DC0064"]},{"channel":"execve: Execution of update-ca-certificates or trust anchor modification commands","analytics":["AN0154"],"data_components":["DC0064"]},{"channel":"execve: Processes launched with LD_PRELOAD/LD_LIBRARY_PATH pointing to non-system dirs","analytics":["AN0053"],"data_components":["DC0032"]},{"channel":"gcore, gdb, strings, hexdump execution","analytics":["AN0157"],"data_components":["DC0064"]},{"channel":"git push, curl -X POST","analytics":["AN0896"],"data_components":["DC0064"]},{"channel":"grep/cat/awk on files with password fields","analytics":["AN0857"],"data_components":["DC0064"]},{"channel":"systemctl spawning managed processes","analytics":["AN0200"],"data_components":["DC0032"]},{"channel":"systemctl stop auditd, kill -9 <pid>, or modifications to /etc/selinux/config","analytics":["AN0887"],"data_components":["DC0032"]}],"data_components":["DC0032","DC0064"],"analytics":["AN0053","AN0056","AN0059","AN0092","AN0154","AN0157","AN0171","AN0200","AN0272","AN0361","AN0385","AN0437","AN0473","AN0505","AN0537","AN0560","AN0710","AN0775","AN0788","AN0828","AN0857","AN0883","AN0887","AN0896","AN0950","AN1002","AN1016","AN1062","AN1085","AN1096","AN1135","AN1199","AN1247","AN1281","AN1326","AN1385","AN1418","AN1512","AN1517","AN1572","AN1584","AN1638","AN2037","AN2039","AN2064"],"techniques":["T1003.005","T1007","T1010","T1014","T1016","T1016.001","T1016.002","T1018","T1021.004","T1021.005","T1027.008","T1027.018","T1129","T1505.002","T1542","T1546.004","T1547.013","T1552.001","T1552.003","T1552.004","T1553","T1553.004","T1554","T1555","T1555.002","T1561","T1561.001","T1561.002","T1563.001","T1564","T1564.001","T1564.002","T1564.003","T1564.014","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1569.003","T1680","T1684","T1685.004","T1687"],"platforms":["Linux"],"kev_cves":["CVE-2017-12637","CVE-2019-11510","CVE-2019-1653","CVE-2021-40449","CVE-2022-26138","CVE-2022-41082","CVE-2023-27532","CVE-2023-38035","CVE-2023-39780","CVE-2023-46805","CVE-2024-11182","CVE-2024-21893","CVE-2024-55591","CVE-2024-57727","CVE-2025-0282","CVE-2025-24054","CVE-2025-32433","CVE-2025-48927","CVE-2025-48928","CVE-2025-54309","CVE-2025-5777"]},{"slug":"wineventlog-sysmon","name":"WinEventLog:Sysmon","channels":[{"channel":"EventCode=1","analytics":["AN0006","AN0009","AN0012","AN0016","AN0021","AN0024","AN0034","AN0037","AN0040","AN0051","AN0055","AN0061","AN0066","AN0071","AN0080","AN0085","AN0089","AN0091","AN0094","AN0100","AN0105","AN0108","AN0109","AN0113","AN0118","AN0127","AN0130","AN0133","AN0137","AN0147","AN0152","AN0153","AN0165","AN0170","AN0172","AN0176","AN0182","AN0184","AN0185","AN0188","AN0191","AN0204","AN0209","AN0216","AN0219","AN0226","AN0229","AN0236","AN0247","AN0250","AN0254","AN0258","AN0263","AN0265","AN0277","AN0278","AN0286","AN0292","AN0297","AN0302","AN0316","AN0324","AN0327","AN0331","AN0334","AN0341","AN0342","AN0355","AN0360","AN0363","AN0372","AN0375","AN0379","AN0388","AN0396","AN0398","AN0411","AN0423","AN0436","AN0455","AN0462","AN0472","AN0478","AN0502","AN0504","AN0510","AN0511","AN0516","AN0531","AN0535","AN0536","AN0540","AN0558","AN0559","AN0568","AN0576","AN0577","AN0580","AN0581","AN0584","AN0589","AN0590","AN0594","AN0595","AN0599","AN0602","AN0609","AN0616","AN0622","AN0628","AN0630","AN0633","AN0637","AN0641","AN0648","AN0651","AN0655","AN0662","AN0692","AN0694","AN0699","AN0724","AN0728","AN0733","AN0741","AN0750","AN0755","AN0767","AN0778","AN0781","AN0782","AN0786","AN0787","AN0791","AN0797","AN0819","AN0822","AN0838","AN0841","AN0842","AN0846","AN0850","AN0854","AN0856","AN0862","AN0868","AN0872","AN0880","AN0895","AN0903","AN0909","AN0913","AN0919","AN0922","AN0931","AN0932","AN0933","AN0940","AN0941","AN0942","AN0943","AN0954","AN0965","AN0968","AN0980","AN0988","AN0995","AN1012","AN1015","AN1020","AN1029","AN1030","AN1031","AN1032","AN1033","AN1045","AN1048","AN1057","AN1064","AN1075","AN1076","AN1095","AN1108","AN1116","AN1118","AN1133","AN1134","AN1144","AN1165","AN1169","AN1182","AN1185","AN1186","AN1195","AN1198","AN1206","AN1211","AN1212","AN1220","AN1221","AN1229","AN1235","AN1245","AN1246","AN1252","AN1259","AN1280","AN1288","AN1305","AN1308","AN1313","AN1319","AN1323","AN1361","AN1366","AN1381","AN1384","AN1389","AN1393","AN1399","AN1407","AN1410","AN1413","AN1417","AN1419","AN1428","AN1434","AN1436","AN1440","AN1448","AN1452","AN1461","AN1464","AN1465","AN1468","AN1472","AN1480","AN1483","AN1489","AN1495","AN1501","AN1507","AN1516","AN1527","AN1531","AN1536","AN1538","AN1543","AN1557","AN1560","AN1561","AN1564","AN1571","AN1575","AN1583","AN1588","AN1593","AN1604","AN1612","AN1620","AN1621","AN1622","AN2035","AN2038","AN2043","AN2063"],"data_components":["DC0032"]},{"channel":"EventCode=10","analytics":["AN0016","AN0030","AN0066","AN0074","AN0095","AN0105","AN0126","AN0237","AN0243","AN0271","AN0277","AN0282","AN0287","AN0292","AN0297","AN0327","AN0378","AN0389","AN0405","AN0430","AN0444","AN0478","AN0493","AN0608","AN0619","AN0648","AN0675","AN0687","AN0719","AN0757","AN0767","AN0786","AN0822","AN0838","AN0913","AN0919","AN0932","AN0941","AN0942","AN0965","AN1000","AN1030","AN1035","AN1076","AN1094","AN1095","AN1182","AN1186","AN1193","AN1198","AN1207","AN1212","AN1213","AN1220","AN1253","AN1288","AN1289","AN1324","AN1353","AN1398","AN1399","AN1402","AN1417","AN1443","AN1465","AN1501","AN1535","AN1593","AN1598","AN1641"],"data_components":["DC0035"]},{"channel":"EventCode=11","analytics":["AN0009","AN0012","AN0021","AN0034","AN0037","AN0040","AN0051","AN0052","AN0055","AN0065","AN0071","AN0072","AN0074","AN0091","AN0094","AN0108","AN0123","AN0130","AN0137","AN0139","AN0162","AN0165","AN0176","AN0178","AN0184","AN0185","AN0188","AN0194","AN0212","AN0229","AN0235","AN0240","AN0247","AN0251","AN0275","AN0278","AN0292","AN0297","AN0320","AN0327","AN0341","AN0342","AN0367","AN0372","AN0375","AN0388","AN0411","AN0428","AN0430","AN0472","AN0484","AN0488","AN0498","AN0510","AN0516","AN0531","AN0540","AN0555","AN0558","AN0568","AN0576","AN0577","AN0580","AN0595","AN0599","AN0602","AN0609","AN0614","AN0616","AN0619","AN0622","AN0629","AN0630","AN0651","AN0655","AN0677","AN0699","AN0712","AN0714","AN0724","AN0747","AN0767","AN0774","AN0782","AN0797","AN0819","AN0831","AN0834","AN0841","AN0854","AN0856","AN0862","AN0872","AN0880","AN0913","AN0932","AN0940","AN0942","AN0949","AN0962","AN0968","AN0983","AN0992","AN1008","AN1028","AN1030","AN1033","AN1040","AN1061","AN1064","AN1070","AN1075","AN1097","AN1108","AN1116","AN1145","AN1153","AN1177","AN1206","AN1207","AN1211","AN1213","AN1216","AN1221","AN1245","AN1246","AN1288","AN1298","AN1303","AN1308","AN1314","AN1319","AN1321","AN1366","AN1381","AN1384","AN1397","AN1407","AN1433","AN1436","AN1458","AN1480","AN1501","AN1511","AN1516","AN1528","AN1531","AN1535","AN1548","AN1551","AN1560","AN1598","AN1610","AN1611","AN2035","AN2063"],"data_components":["DC0039"]},{"channel":"EventCode=12","analytics":["AN0153","AN0323","AN0558","AN0622","AN0629","AN0871","AN0886","AN0932","AN1028","AN1186","AN1366","AN2043"],"data_components":["DC0056"]},{"channel":"EventCode=13","analytics":["AN0580"],"data_components":["DC0063"]},{"channel":"EventCode=13, 14","analytics":["AN0021","AN0074","AN0094","AN0118","AN0123","AN0137","AN0170","AN0235","AN0240","AN0243","AN0251","AN0323","AN0341","AN0360","AN0406","AN0441","AN0520","AN0535","AN0589","AN0622","AN0629","AN0687","AN0694","AN0764","AN0778","AN0781","AN0862","AN0871","AN0880","AN0932","AN0933","AN0975","AN1001","AN1028","AN1030","AN1032","AN1094","AN1116","AN1153","AN1185","AN1221","AN1271","AN1366","AN1369","AN1384","AN1436","AN1452","AN1527","AN1536","AN1551","AN1575","AN1595","AN2043"],"data_components":["DC0063"]},{"channel":"EventCode=15","analytics":["AN0094","AN0108","AN0162","AN0176","AN0378","AN0510","AN0555","AN0577","AN0702","AN0712","AN0819","AN0872","AN1097","AN1134","AN1206","AN1211","AN1436","AN1560","AN1626","AN1641"],"data_components":["DC0059"]},{"channel":"EventCode=16","analytics":["AN0667"],"data_components":["DC0018"]},{"channel":"EventCode=17","analytics":["AN0513","AN1095","AN1357"],"data_components":["DC0048"]},{"channel":"EventCode=2","analytics":["AN0137","AN0162","AN0229","AN0235","AN0258","AN0510","AN0602","AN0629","AN0949","AN1245","AN1402","AN1405","AN1611"],"data_components":["DC0061"]},{"channel":"EventCode=23","analytics":["AN0392","AN0411","AN0469","AN0520","AN0555","AN0737","AN1216","AN1472"],"data_components":["DC0040"]},{"channel":"EventCode=25","analytics":["AN1305"],"data_components":["DC0035"]},{"channel":"EventCode=3, 22","analytics":["AN0002","AN0030","AN0052","AN0071","AN0075","AN0080","AN0100","AN0109","AN0118","AN0123","AN0130","AN0131","AN0158","AN0165","AN0178","AN0185","AN0204","AN0212","AN0216","AN0219","AN0226","AN0251","AN0274","AN0298","AN0302","AN0320","AN0327","AN0331","AN0345","AN0346","AN0367","AN0379","AN0400","AN0423","AN0436","AN0445","AN0462","AN0485","AN0488","AN0489","AN0498","AN0513","AN0564","AN0568","AN0576","AN0590","AN0596","AN0622","AN0637","AN0651","AN0655","AN0677","AN0702","AN0714","AN0728","AN0741","AN0750","AN0759","AN0785","AN0787","AN0791","AN0797","AN0823","AN0842","AN0862","AN0895","AN0922","AN0927","AN0928","AN0931","AN0932","AN0962","AN0968","AN0969","AN0988","AN1004","AN1020","AN1028","AN1031","AN1057","AN1091","AN1113","AN1118","AN1121","AN1134","AN1140","AN1144","AN1169","AN1178","AN1185","AN1189","AN1207","AN1225","AN1229","AN1254","AN1294","AN1305","AN1308","AN1309","AN1314","AN1331","AN1335","AN1344","AN1366","AN1367","AN1376","AN1381","AN1389","AN1397","AN1398","AN1407","AN1413","AN1434","AN1448","AN1464","AN1468","AN1483","AN1489","AN1496","AN1511","AN1535","AN1548","AN1551","AN1564","AN1571","AN1583","AN1599","AN1610","AN1620","AN2029","AN2035","AN2043","AN2063"],"data_components":["DC0082"]},{"channel":"EventCode=4","analytics":["AN0061"],"data_components":["DC0041"]},{"channel":"EventCode=5","analytics":["AN0045","AN1369"],"data_components":["DC0033"]},{"channel":"EventCode=6","analytics":["AN0185","AN0384","AN0462","AN0474","AN0629","AN0827","AN0862","AN0882","AN0916","AN1035","AN1061","AN1419","AN1527","AN2038"],"data_components":["DC0079"]},{"channel":"EventCode=7","analytics":["AN0016","AN0021","AN0048","AN0051","AN0052","AN0071","AN0074","AN0085","AN0108","AN0118","AN0127","AN0184","AN0185","AN0209","AN0219","AN0226","AN0236","AN0237","AN0250","AN0263","AN0287","AN0327","AN0341","AN0388","AN0389","AN0396","AN0400","AN0430","AN0445","AN0462","AN0472","AN0478","AN0488","AN0502","AN0550","AN0558","AN0568","AN0577","AN0578","AN0580","AN0581","AN0583","AN0595","AN0609","AN0622","AN0628","AN0643","AN0733","AN0747","AN0757","AN0759","AN0785","AN0791","AN0814","AN0831","AN0838","AN0862","AN0880","AN0919","AN0968","AN0980","AN1000","AN1028","AN1029","AN1035","AN1048","AN1094","AN1095","AN1133","AN1207","AN1212","AN1220","AN1222","AN1252","AN1288","AN1289","AN1303","AN1305","AN1308","AN1319","AN1323","AN1335","AN1393","AN1398","AN1399","AN1433","AN1458","AN1464","AN1465","AN1480","AN1495","AN1496","AN1535","AN1536","AN1551","AN1588","AN1598","AN1633","AN2063"],"data_components":["DC0016"]},{"channel":"EventCode=8","analytics":["AN0277","AN0297","AN0389","AN0822","AN0941","AN1076","AN1289","AN1398","AN1535","AN1551"],"data_components":["DC0020"]},{"channel":"EventCode=9","analytics":["AN0275","AN0428","AN0774"],"data_components":["DC0054"]},{"channel":"File creation of suspicious scripts/binaries in temporary directories","analytics":["AN0993"],"data_components":["DC0039"]},{"channel":"Outbound requests with forged tokens/cookies in headers","analytics":["AN0720"],"data_components":["DC0085"]},{"channel":"Raw disk write access via \\\\.\\PhysicalDrive* or \\\\.\\C:","analytics":["AN0384"],"data_components":["DC0046"]},{"channel":"Raw disk writes targeting \\\\.\\PhysicalDrive* or MBR locations","analytics":["AN0882"],"data_components":["DC0046"]},{"channel":"Raw write attempts targeting \\\\.\\PhysicalDrive0 or sector 0 (MBR/partition table)","analytics":["AN0827"],"data_components":["DC0046"]}],"data_components":["DC0016","DC0018","DC0020","DC0032","DC0033","DC0035","DC0039","DC0040","DC0041","DC0046","DC0048","DC0054","DC0056","DC0059","DC0061","DC0063","DC0079","DC0082","DC0085"],"analytics":["AN0002","AN0006","AN0009","AN0012","AN0016","AN0021","AN0024","AN0030","AN0034","AN0037","AN0040","AN0045","AN0048","AN0051","AN0052","AN0055","AN0061","AN0065","AN0066","AN0071","AN0072","AN0074","AN0075","AN0080","AN0085","AN0089","AN0091","AN0094","AN0095","AN0100","AN0105","AN0108","AN0109","AN0113","AN0118","AN0123","AN0126","AN0127","AN0130","AN0131","AN0133","AN0137","AN0139","AN0147","AN0152","AN0153","AN0158","AN0162","AN0165","AN0170","AN0172","AN0176","AN0178","AN0182","AN0184","AN0185","AN0188","AN0191","AN0194","AN0204","AN0209","AN0212","AN0216","AN0219","AN0226","AN0229","AN0235","AN0236","AN0237","AN0240","AN0243","AN0247","AN0250","AN0251","AN0254","AN0258","AN0263","AN0265","AN0271","AN0274","AN0275","AN0277","AN0278","AN0282","AN0286","AN0287","AN0292","AN0297","AN0298","AN0302","AN0316","AN0320","AN0323","AN0324","AN0327","AN0331","AN0334","AN0341","AN0342","AN0345","AN0346","AN0355","AN0360","AN0363","AN0367","AN0372","AN0375","AN0378","AN0379","AN0384","AN0388","AN0389","AN0392","AN0396","AN0398","AN0400","AN0405","AN0406","AN0411","AN0423","AN0428","AN0430","AN0436","AN0441","AN0444","AN0445","AN0455","AN0462","AN0469","AN0472","AN0474","AN0478","AN0484","AN0485","AN0488","AN0489","AN0493","AN0498","AN0502","AN0504","AN0510","AN0511","AN0513","AN0516","AN0520","AN0531","AN0535","AN0536","AN0540","AN0550","AN0555","AN0558","AN0559","AN0564","AN0568","AN0576","AN0577","AN0578","AN0580","AN0581","AN0583","AN0584","AN0589","AN0590","AN0594","AN0595","AN0596","AN0599","AN0602","AN0608","AN0609","AN0614","AN0616","AN0619","AN0622","AN0628","AN0629","AN0630","AN0633","AN0637","AN0641","AN0643","AN0648","AN0651","AN0655","AN0662","AN0667","AN0675","AN0677","AN0687","AN0692","AN0694","AN0699","AN0702","AN0712","AN0714","AN0719","AN0720","AN0724","AN0728","AN0733","AN0737","AN0741","AN0747","AN0750","AN0755","AN0757","AN0759","AN0764","AN0767","AN0774","AN0778","AN0781","AN0782","AN0785","AN0786","AN0787","AN0791","AN0797","AN0814","AN0819","AN0822","AN0823","AN0827","AN0831","AN0834","AN0838","AN0841","AN0842","AN0846","AN0850","AN0854","AN0856","AN0862","AN0868","AN0871","AN0872","AN0880","AN0882","AN0886","AN0895","AN0903","AN0909","AN0913","AN0916","AN0919","AN0922","AN0927","AN0928","AN0931","AN0932","AN0933","AN0940","AN0941","AN0942","AN0943","AN0949","AN0954","AN0962","AN0965","AN0968","AN0969","AN0975","AN0980","AN0983","AN0988","AN0992","AN0993","AN0995","AN1000","AN1001","AN1004","AN1008","AN1012","AN1015","AN1020","AN1028","AN1029","AN1030","AN1031","AN1032","AN1033","AN1035","AN1040","AN1045","AN1048","AN1057","AN1061","AN1064","AN1070","AN1075","AN1076","AN1091","AN1094","AN1095","AN1097","AN1108","AN1113","AN1116","AN1118","AN1121","AN1133","AN1134","AN1140","AN1144","AN1145","AN1153","AN1165","AN1169","AN1177","AN1178","AN1182","AN1185","AN1186","AN1189","AN1193","AN1195","AN1198","AN1206","AN1207","AN1211","AN1212","AN1213","AN1216","AN1220","AN1221","AN1222","AN1225","AN1229","AN1235","AN1245","AN1246","AN1252","AN1253","AN1254","AN1259","AN1271","AN1280","AN1288","AN1289","AN1294","AN1298","AN1303","AN1305","AN1308","AN1309","AN1313","AN1314","AN1319","AN1321","AN1323","AN1324","AN1331","AN1335","AN1344","AN1353","AN1357","AN1361","AN1366","AN1367","AN1369","AN1376","AN1381","AN1384","AN1389","AN1393","AN1397","AN1398","AN1399","AN1402","AN1405","AN1407","AN1410","AN1413","AN1417","AN1419","AN1428","AN1433","AN1434","AN1436","AN1440","AN1443","AN1448","AN1452","AN1458","AN1461","AN1464","AN1465","AN1468","AN1472","AN1480","AN1483","AN1489","AN1495","AN1496","AN1501","AN1507","AN1511","AN1516","AN1527","AN1528","AN1531","AN1535","AN1536","AN1538","AN1543","AN1548","AN1551","AN1557","AN1560","AN1561","AN1564","AN1571","AN1575","AN1583","AN1588","AN1593","AN1595","AN1598","AN1599","AN1604","AN1610","AN1611","AN1612","AN1620","AN1621","AN1622","AN1626","AN1633","AN1641","AN2029","AN2035","AN2038","AN2043","AN2063"],"techniques":["T1001.001","T1001.002","T1001.003","T1003","T1003.001","T1003.002","T1003.003","T1003.004","T1003.005","T1005","T1006","T1008","T1010","T1011","T1011.001","T1012","T1014","T1016","T1016.001","T1016.002","T1018","T1020","T1021","T1021.001","T1021.002","T1021.003","T1021.005","T1021.006","T1021.008","T1025","T1027","T1027.001","T1027.002","T1027.003","T1027.004","T1027.005","T1027.006","T1027.007","T1027.008","T1027.009","T1027.012","T1027.013","T1027.014","T1027.015","T1027.016","T1027.017","T1027.018","T1029","T1030","T1033","T1036","T1036.001","T1036.002","T1036.003","T1036.004","T1036.005","T1036.007","T1036.008","T1036.012","T1039","T1041","T1046","T1047","T1048","T1048.001","T1048.002","T1048.003","T1049","T1052","T1052.001","T1053","T1053.002","T1053.005","T1055","T1055.001","T1055.002","T1055.003","T1055.004","T1055.005","T1055.011","T1055.012","T1055.013","T1055.015","T1056","T1056.001","T1056.002","T1056.003","T1056.004","T1057","T1059","T1059.001","T1059.003","T1059.005","T1059.006","T1059.007","T1059.010","T1059.011","T1068","T1070","T1070.003","T1070.004","T1070.005","T1070.006","T1070.007","T1070.008","T1070.009","T1070.010","T1071","T1071.001","T1071.002","T1071.003","T1071.004","T1071.005","T1074","T1074.001","T1074.002","T1078","T1078.002","T1080","T1082","T1083","T1087","T1087.001","T1087.002","T1087.003","T1090","T1090.001","T1090.002","T1090.003","T1090.004","T1091","T1092","T1095","T1098","T1102","T1102.001","T1102.002","T1102.003","T1104","T1105","T1106","T1110.002","T1111","T1112","T1113","T1114","T1114.001","T1114.002","T1115","T1119","T1120","T1123","T1124","T1125","T1127","T1127.001","T1127.002","T1127.003","T1129","T1132","T1132.001","T1132.002","T1133","T1134","T1134.001","T1134.002","T1135","T1136","T1136.001","T1136.002","T1137","T1137.001","T1137.002","T1137.003","T1137.004","T1137.005","T1137.006","T1140","T1176","T1176.001","T1176.002","T1185","T1187","T1189","T1190","T1195","T1195.001","T1195.002","T1195.003","T1197","T1199","T1200","T1201","T1202","T1203","T1204","T1204.001","T1204.002","T1204.003","T1204.004","T1204.005","T1205","T1205.001","T1205.002","T1210","T1211","T1212","T1213.006","T1216","T1216.001","T1216.002","T1217","T1218","T1218.001","T1218.002","T1218.003","T1218.004","T1218.005","T1218.007","T1218.008","T1218.009","T1218.010","T1218.011","T1218.012","T1218.013","T1218.014","T1218.015","T1219","T1219.001","T1219.002","T1220","T1221","T1222","T1222.001","T1480","T1480.001","T1480.002","T1482","T1484","T1484.001","T1484.002","T1485","T1486","T1489","T1490","T1491","T1491.001","T1491.002","T1495","T1496","T1496.001","T1496.002","T1497","T1497.001","T1497.002","T1497.003","T1498","T1498.001","T1498.002","T1499","T1499.001","T1499.002","T1499.003","T1499.004","T1505","T1505.001","T1505.002","T1505.003","T1505.004","T1505.005","T1518.001","T1518.002","T1529","T1531","T1534","T1539","T1542","T1542.001","T1542.002","T1542.003","T1543","T1543.003","T1546","T1546.001","T1546.002","T1546.003","T1546.007","T1546.008","T1546.009","T1546.010","T1546.011","T1546.012","T1546.013","T1546.015","T1546.016","T1547","T1547.001","T1547.002","T1547.003","T1547.004","T1547.005","T1547.008","T1547.009","T1547.010","T1547.012","T1547.014","T1548","T1548.002","T1550","T1550.002","T1550.003","T1552","T1552.001","T1552.002","T1552.004","T1552.006","T1553","T1553.002","T1553.003","T1553.004","T1553.005","T1554","T1555","T1555.003","T1555.004","T1555.005","T1556","T1556.001","T1556.002","T1556.005","T1556.007","T1556.008","T1557","T1557.002","T1558","T1558.001","T1558.002","T1558.003","T1558.004","T1559","T1559.001","T1559.002","T1560","T1560.001","T1560.002","T1560.003","T1561","T1561.001","T1561.002","T1563","T1563.002","T1564","T1564.001","T1564.002","T1564.003","T1564.004","T1564.005","T1564.006","T1564.007","T1564.010","T1564.011","T1564.012","T1565","T1565.001","T1565.002","T1565.003","T1566","T1566.001","T1566.002","T1566.003","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1568","T1568.001","T1568.002","T1568.003","T1569","T1569.002","T1570","T1571","T1572","T1573","T1573.001","T1573.002","T1574","T1574.001","T1574.005","T1574.007","T1574.008","T1574.009","T1574.010","T1574.011","T1574.012","T1574.013","T1574.014","T1606","T1606.001","T1611","T1614.001","T1615","T1620","T1622","T1652","T1657","T1659","T1667","T1668","T1678","T1680","T1684","T1685","T1685.001","T1685.003","T1685.005","T1686","T1686.003","T1687","T1688","T1689","T1690"],"platforms":["IaaS","Linux","Office Suite","Windows","macOS"],"kev_cves":["CVE-2007-5659","CVE-2008-0655","CVE-2008-2992","CVE-2009-1862","CVE-2009-3953","CVE-2009-3960","CVE-2009-4324","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2011-2462","CVE-2012-0754","CVE-2012-0767","CVE-2012-1535","CVE-2012-2034","CVE-2012-5054","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0640","CVE-2013-0641","CVE-2013-3346","CVE-2014-0496","CVE-2014-0546","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-3113","CVE-2015-5119","CVE-2015-7645","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1010","CVE-2016-1019","CVE-2016-4117","CVE-2016-4437","CVE-2016-7855","CVE-2017-11292","CVE-2017-11882","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-0296","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-15982","CVE-2018-4878","CVE-2018-4939","CVE-2018-4990","CVE-2018-6789","CVE-2018-7600","CVE-2019-0211","CVE-2019-0604","CVE-2019-0708","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2019-19781","CVE-2019-3396","CVE-2019-3398","CVE-2019-5591","CVE-2020-0069","CVE-2020-0688","CVE-2020-0787","CVE-2020-12812","CVE-2020-1472","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3452","CVE-2020-3580","CVE-2020-5735","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2020-8657","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21017","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22899","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26855","CVE-2021-26857","CVE-2021-26858","CVE-2021-27059","CVE-2021-27065","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-28550","CVE-2021-29256","CVE-2021-30554","CVE-2021-31166","CVE-2021-31207","CVE-2021-3129","CVE-2021-32030","CVE-2021-33739","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-36934","CVE-2021-37415","CVE-2021-37975","CVE-2021-39144","CVE-2021-39226","CVE-2021-4034","CVE-2021-40449","CVE-2021-40539","CVE-2021-40655","CVE-2021-41379","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45046","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-1388","CVE-2022-20699","CVE-2022-20700","CVE-2022-20701","CVE-2022-20703","CVE-2022-20708","CVE-2022-20821","CVE-2022-21919","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22947","CVE-2022-22948","CVE-2022-22954","CVE-2022-22960","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24086","CVE-2022-24521","CVE-2022-24682","CVE-2022-26134","CVE-2022-26138","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-30190","CVE-2022-3038","CVE-2022-3075","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-40684","CVE-2022-41033","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2022-47966","CVE-2023-0386","CVE-2023-0669","CVE-2023-1389","CVE-2023-20109","CVE-2023-20118","CVE-2023-20198","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-2136","CVE-2023-21608","CVE-2023-21674","CVE-2023-21715","CVE-2023-22515","CVE-2023-22518","CVE-2023-22527","CVE-2023-22952","CVE-2023-23397","CVE-2023-2533","CVE-2023-26359","CVE-2023-26360","CVE-2023-26369","CVE-2023-27350","CVE-2023-27524","CVE-2023-27532","CVE-2023-27997","CVE-2023-28229","CVE-2023-28252","CVE-2023-2868","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-32315","CVE-2023-33246","CVE-2023-33538","CVE-2023-34048","CVE-2023-34192","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-39780","CVE-2023-40044","CVE-2023-41179","CVE-2023-42793","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-4966","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-6548","CVE-2023-6549","CVE-2023-7024","CVE-2023-7101","CVE-2024-0769","CVE-2024-11120","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20359","CVE-2024-20399","CVE-2024-20439","CVE-2024-20953","CVE-2024-21413","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-26169","CVE-2024-27198","CVE-2024-27443","CVE-2024-29059","CVE-2024-30051","CVE-2024-34102","CVE-2024-37085","CVE-2024-38080","CVE-2024-38112","CVE-2024-38475","CVE-2024-40890","CVE-2024-40891","CVE-2024-41710","CVE-2024-41713","CVE-2024-42009","CVE-2024-4358","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-48248","CVE-2024-4879","CVE-2024-4885","CVE-2024-49035","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-50603","CVE-2024-5217","CVE-2024-5274","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-55591","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-0411","CVE-2025-0994","CVE-2025-1316","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21480","CVE-2025-21590","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24054","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-24991","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27038","CVE-2025-27363","CVE-2025-2783","CVE-2025-30397","CVE-2025-30400","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-34028","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-48927","CVE-2025-48928","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"wineventlog-security","name":"WinEventLog:Security","channels":[{"channel":"ARP cache modification attempts observed through event tracing or security baselines","analytics":["AN1091"],"data_components":["DC0078"]},{"channel":"Anomalous logon without MFA enforcement","analytics":["AN0814"],"data_components":["DC0067"]},{"channel":"Device Object Creation","analytics":["AN0104"],"data_components":["DC0087"]},{"channel":"EventCode=1","analytics":["AN1331"],"data_components":["DC0032"]},{"channel":"EventCode=1074","analytics":["AN1538"],"data_components":["DC0018"]},{"channel":"EventCode=1102","analytics":["AN0520","AN0535","AN1472"],"data_components":["DC0038"]},{"channel":"EventCode=1166, 7045","analytics":["AN1035"],"data_components":["DC0018"]},{"channel":"EventCode=3033","analytics":["AN0629"],"data_components":["DC0016"]},{"channel":"EventCode=4103, 4104, 4105, 4106","analytics":["AN0151"],"data_components":["DC0064"]},{"channel":"EventCode=4624","analytics":["AN1543"],"data_components":["DC0067"]},{"channel":"EventCode=4624, 4625, 4768, 4769","analytics":["AN0590"],"data_components":["DC0088"]},{"channel":"EventCode=4624, 4648","analytics":["AN0147","AN0199","AN0216","AN0286","AN0420","AN0444","AN0484","AN0498","AN0504","AN0687","AN0719","AN0750","AN0757","AN0791","AN0792","AN0856","AN0931","AN0954","AN1000","AN1108","AN1137","AN1144","AN1283","AN1305","AN1313","AN1344","AN1361","AN1398","AN1468","AN1551","AN1620","AN2035"],"data_components":["DC0067"]},{"channel":"EventCode=4625","analytics":["AN0147","AN0451","AN1262","AN1521"],"data_components":["DC0002"]},{"channel":"EventCode=4625, 4771, 4648","analytics":["AN1336"],"data_components":["DC0002"]},{"channel":"EventCode=4648","analytics":["AN1551"],"data_components":["DC0002"]},{"channel":"EventCode=4657","analytics":["AN0009","AN0024","AN0051","AN0113","AN0153","AN0176","AN0287","AN0311","AN0577","AN0583","AN0595","AN0609","AN0667","AN0671","AN0909","AN0973","AN0995","AN1029","AN1097","AN1186","AN1195","AN1222","AN1246","AN1303","AN1319","AN1323","AN1446","AN1495","AN1561","AN1588","AN1598"],"data_components":["DC0050","DC0063"]},{"channel":"EventCode=4661","analytics":["AN0152"],"data_components":["DC0071"]},{"channel":"EventCode=4662","analytics":["AN0016","AN0455","AN0648","AN0770","AN1632"],"data_components":["DC0071"]},{"channel":"EventCode=4663, 4656, 4658","analytics":["AN1177"],"data_components":["DC0059"]},{"channel":"EventCode=4663, 4670, 4656","analytics":["AN0040","AN0065","AN0105","AN0130","AN0133","AN0139","AN0162","AN0184","AN0199","AN0229","AN0243","AN0282","AN0292","AN0331","AN0342","AN0392","AN0423","AN0436","AN0469","AN0555","AN0568","AN0616","AN0628","AN0648","AN0662","AN0705","AN0712","AN0724","AN0737","AN0755","AN0787","AN0823","AN0834","AN0854","AN0895","AN0988","AN1177","AN1198","AN1212","AN1271","AN1344","AN1357","AN1393","AN1410","AN1413","AN1417","AN1528","AN1571","AN1622","AN1626","AN2030"],"data_components":["DC0021","DC0035","DC0038","DC0050","DC0055","DC0059","DC0061","DC0063","DC0066"]},{"channel":"EventCode=4672","analytics":["AN0061","AN0147","AN0170","AN0444","AN0871","AN0975","AN1094","AN1137","AN1375","AN1398","AN1419"],"data_components":["DC0088"]},{"channel":"EventCode=4672, 4634","analytics":["AN0405","AN0675","AN0786","AN1253","AN1443"],"data_components":["DC0088"]},{"channel":"EventCode=4673","analytics":["AN0384","AN0827","AN0882","AN1030","AN1398"],"data_components":["DC0013"]},{"channel":"EventCode=4688","analytics":["AN0045","AN0048","AN0052","AN0095","AN0119","AN0123","AN0126","AN0178","AN0199","AN0235","AN0237","AN0240","AN0251","AN0274","AN0275","AN0298","AN0311","AN0317","AN0320","AN0323","AN0345","AN0367","AN0378","AN0406","AN0430","AN0441","AN0445","AN0474","AN0488","AN0498","AN0507","AN0513","AN0550","AN0574","AN0578","AN0608","AN0614","AN0619","AN0623","AN0643","AN0677","AN0705","AN0747","AN0764","AN0774","AN0785","AN0831","AN0834","AN0871","AN0875","AN0886","AN0927","AN0949","AN0962","AN0969","AN0975","AN0983","AN0992","AN1025","AN1028","AN1034","AN1040","AN1052","AN1064","AN1070","AN1094","AN1100","AN1113","AN1153","AN1174","AN1177","AN1178","AN1193","AN1207","AN1213","AN1253","AN1314","AN1324","AN1325","AN1335","AN1351","AN1353","AN1375","AN1394","AN1397","AN1402","AN1433","AN1446","AN1452","AN1458","AN1511","AN1528","AN1535","AN1548","AN1551","AN1567","AN1589","AN1595","AN1610","AN1611","AN1612","AN1633","AN1641","AN2030","AN2038","AN2043","AN2063"],"data_components":["DC0032"]},{"channel":"EventCode=4697","analytics":["AN0778","AN1185","AN1274","AN1527","AN1575"],"data_components":["DC0060"]},{"channel":"EventCode=4698","analytics":["AN0024","AN0258","AN0324","AN0943","AN1221","AN1489","AN1507"],"data_components":["DC0001"]},{"channel":"EventCode=4702","analytics":["AN1221"],"data_components":["DC0012"]},{"channel":"EventCode=4704","analytics":["AN0854","AN1259"],"data_components":["DC0010"]},{"channel":"EventCode=4720","analytics":["AN0006","AN1001","AN1077","AN1235","AN1604"],"data_components":["DC0014"]},{"channel":"EventCode=4720, 4738","analytics":["AN0383"],"data_components":["DC0013"]},{"channel":"EventCode=4723, 4724, 4740","analytics":["AN0334"],"data_components":["DC0010"]},{"channel":"EventCode=4726, 4657","analytics":["AN0113"],"data_components":["DC0009"]},{"channel":"EventCode=4728, 4729, 4732, 4733, 4756, 4757","analytics":["AN0865"],"data_components":["DC0010"]},{"channel":"EventCode=4738, 4728, 4670","analytics":["AN0265"],"data_components":["DC0010"]},{"channel":"EventCode=4739","analytics":["AN0543","AN1621"],"data_components":["DC0066"]},{"channel":"EventCode=4768","analytics":["AN0316","AN0671","AN1000","AN1144"],"data_components":["DC0084"]},{"channel":"EventCode=4768, 4769, 4770","analytics":["AN0493"],"data_components":["DC0002"]},{"channel":"EventCode=4769","analytics":["AN0405","AN0444","AN1000"],"data_components":["DC0002","DC0084"]},{"channel":"EventCode=4769, 1200, 1202","analytics":["AN0418"],"data_components":["DC0002"]},{"channel":"EventCode=4776, 4625","analytics":["AN1004","AN1275","AN1476","AN1543"],"data_components":["DC0002"]},{"channel":"EventCode=4776, 4771, 4770","analytics":["AN1344"],"data_components":["DC0088"]},{"channel":"EventCode=4778, EventCode=4779","analytics":["AN0931"],"data_components":["DC0088"]},{"channel":"EventCode=4798, 4799","analytics":["AN1612"],"data_components":["DC0099"]},{"channel":"EventCode=4800, 4801","analytics":["AN1182"],"data_components":["DC0088"]},{"channel":"EventCode=4928","analytics":["AN0770"],"data_components":["DC0087"]},{"channel":"EventCode=4929","analytics":["AN0770","AN1632"],"data_components":["DC0068","DC0084"]},{"channel":"EventCode=5136","analytics":["AN0383","AN0755","AN0786","AN0814","AN0854","AN1253","AN1259"],"data_components":["DC0066"]},{"channel":"EventCode=5140","analytics":["AN0516"],"data_components":["DC0102"]},{"channel":"EventCode=5145","analytics":["AN1034","AN1075","AN1145","AN1160","AN1298","AN1309","AN1516"],"data_components":["DC0102"]},{"channel":"EventCode=5156, 5157","analytics":["AN0633","AN1015","AN1148","AN2043"],"data_components":["DC0082"]},{"channel":"EventCode=6416","analytics":["AN0185"],"data_components":["DC0038"]},{"channel":"Firewall Rule Modification","analytics":["AN0133"],"data_components":["DC0051"]},{"channel":"Registry key modification HKLM\\Software\\Policies\\Microsoft\\Windows NT\\DNSClient\\EnableMulticast","analytics":["AN1274"],"data_components":["DC0063"]},{"channel":"modification to Winlogon registry keys such as Shell, Notify, or Userinit","analytics":["AN1133"],"data_components":["DC0063"]}],"data_components":["DC0001","DC0002","DC0009","DC0010","DC0012","DC0013","DC0014","DC0016","DC0018","DC0021","DC0032","DC0035","DC0038","DC0050","DC0051","DC0055","DC0059","DC0060","DC0061","DC0063","DC0064","DC0066","DC0067","DC0068","DC0071","DC0078","DC0082","DC0084","DC0087","DC0088","DC0099","DC0102"],"analytics":["AN0006","AN0009","AN0016","AN0024","AN0040","AN0045","AN0048","AN0051","AN0052","AN0061","AN0065","AN0095","AN0104","AN0105","AN0113","AN0119","AN0123","AN0126","AN0130","AN0133","AN0139","AN0147","AN0151","AN0152","AN0153","AN0162","AN0170","AN0176","AN0178","AN0184","AN0185","AN0199","AN0216","AN0229","AN0235","AN0237","AN0240","AN0243","AN0251","AN0258","AN0265","AN0274","AN0275","AN0282","AN0286","AN0287","AN0292","AN0298","AN0311","AN0316","AN0317","AN0320","AN0323","AN0324","AN0331","AN0334","AN0342","AN0345","AN0367","AN0378","AN0383","AN0384","AN0392","AN0405","AN0406","AN0418","AN0420","AN0423","AN0430","AN0436","AN0441","AN0444","AN0445","AN0451","AN0455","AN0469","AN0474","AN0484","AN0488","AN0493","AN0498","AN0504","AN0507","AN0513","AN0516","AN0520","AN0535","AN0543","AN0550","AN0555","AN0568","AN0574","AN0577","AN0578","AN0583","AN0590","AN0595","AN0608","AN0609","AN0614","AN0616","AN0619","AN0623","AN0628","AN0629","AN0633","AN0643","AN0648","AN0662","AN0667","AN0671","AN0675","AN0677","AN0687","AN0705","AN0712","AN0719","AN0724","AN0737","AN0747","AN0750","AN0755","AN0757","AN0764","AN0770","AN0774","AN0778","AN0785","AN0786","AN0787","AN0791","AN0792","AN0814","AN0823","AN0827","AN0831","AN0834","AN0854","AN0856","AN0865","AN0871","AN0875","AN0882","AN0886","AN0895","AN0909","AN0927","AN0931","AN0943","AN0949","AN0954","AN0962","AN0969","AN0973","AN0975","AN0983","AN0988","AN0992","AN0995","AN1000","AN1001","AN1004","AN1015","AN1025","AN1028","AN1029","AN1030","AN1034","AN1035","AN1040","AN1052","AN1064","AN1070","AN1075","AN1077","AN1091","AN1094","AN1097","AN1100","AN1108","AN1113","AN1133","AN1137","AN1144","AN1145","AN1148","AN1153","AN1160","AN1174","AN1177","AN1178","AN1182","AN1185","AN1186","AN1193","AN1195","AN1198","AN1207","AN1212","AN1213","AN1221","AN1222","AN1235","AN1246","AN1253","AN1259","AN1262","AN1271","AN1274","AN1275","AN1283","AN1298","AN1303","AN1305","AN1309","AN1313","AN1314","AN1319","AN1323","AN1324","AN1325","AN1331","AN1335","AN1336","AN1344","AN1351","AN1353","AN1357","AN1361","AN1375","AN1393","AN1394","AN1397","AN1398","AN1402","AN1410","AN1413","AN1417","AN1419","AN1433","AN1443","AN1446","AN1452","AN1458","AN1468","AN1472","AN1476","AN1489","AN1495","AN1507","AN1511","AN1516","AN1521","AN1527","AN1528","AN1535","AN1538","AN1543","AN1548","AN1551","AN1561","AN1567","AN1571","AN1575","AN1588","AN1589","AN1595","AN1598","AN1604","AN1610","AN1611","AN1612","AN1620","AN1621","AN1622","AN1626","AN1632","AN1633","AN1641","AN2030","AN2035","AN2038","AN2043","AN2063"],"techniques":["T1003","T1003.001","T1003.002","T1003.003","T1003.004","T1003.005","T1003.006","T1005","T1006","T1007","T1016.001","T1020","T1021","T1021.001","T1021.002","T1021.003","T1021.005","T1021.006","T1025","T1027","T1027.001","T1027.003","T1027.010","T1027.011","T1027.013","T1027.018","T1036.004","T1036.005","T1036.010","T1037","T1037.001","T1037.003","T1039","T1040","T1041","T1048","T1048.002","T1048.003","T1052","T1052.001","T1053","T1053.002","T1053.005","T1055.011","T1056","T1056.001","T1057","T1059.003","T1068","T1069","T1069.001","T1069.002","T1070","T1070.003","T1070.004","T1070.005","T1070.006","T1070.007","T1070.008","T1070.009","T1072","T1074","T1074.001","T1078","T1078.001","T1078.002","T1078.003","T1080","T1082","T1083","T1087","T1098","T1098.002","T1098.005","T1098.007","T1110","T1110.001","T1110.002","T1110.003","T1110.004","T1111","T1114","T1114.001","T1114.003","T1120","T1123","T1124","T1125","T1127","T1127.001","T1127.002","T1127.003","T1129","T1132.001","T1132.002","T1133","T1134","T1134.001","T1134.002","T1134.003","T1134.004","T1134.005","T1135","T1136","T1136.001","T1136.002","T1176","T1176.001","T1176.002","T1185","T1187","T1189","T1195.003","T1197","T1199","T1200","T1201","T1204","T1204.001","T1204.004","T1207","T1211","T1212","T1213","T1213.006","T1218.005","T1218.007","T1218.008","T1218.009","T1218.010","T1218.013","T1222","T1222.001","T1480","T1480.001","T1482","T1484","T1484.001","T1484.002","T1489","T1491","T1491.001","T1491.002","T1495","T1496.001","T1497.002","T1498.001","T1505","T1505.003","T1505.004","T1505.005","T1518","T1518.001","T1518.002","T1529","T1531","T1534","T1539","T1542","T1542.001","T1543","T1543.003","T1546","T1546.001","T1546.002","T1546.007","T1546.009","T1546.011","T1546.012","T1546.015","T1547","T1547.002","T1547.004","T1547.005","T1547.008","T1547.014","T1548","T1548.002","T1550","T1550.002","T1550.003","T1552","T1552.001","T1552.004","T1552.006","T1553","T1553.002","T1553.003","T1553.004","T1553.005","T1553.006","T1554","T1555","T1555.003","T1555.004","T1555.005","T1556","T1556.001","T1556.002","T1556.005","T1556.006","T1556.007","T1556.008","T1557","T1557.001","T1557.002","T1558","T1558.001","T1558.002","T1558.003","T1558.004","T1559","T1559.001","T1559.002","T1560","T1560.001","T1560.002","T1560.003","T1561","T1561.001","T1561.002","T1563","T1563.002","T1564.002","T1564.005","T1564.006","T1564.010","T1564.012","T1565","T1565.001","T1565.003","T1566.002","T1566.003","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1568.001","T1568.002","T1569","T1569.002","T1570","T1571","T1574","T1574.001","T1574.007","T1574.009","T1574.011","T1574.012","T1574.014","T1606","T1606.001","T1606.002","T1611","T1614","T1614.001","T1615","T1621","T1649","T1652","T1653","T1654","T1657","T1659","T1665","T1668","T1669","T1673","T1674","T1679","T1684","T1684.001","T1685.001","T1685.005","T1686","T1686.003","T1687","T1688","T1689"],"platforms":["Identity Provider","Office Suite","Windows"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2010-2883","CVE-2012-0767","CVE-2012-2034","CVE-2012-5054","CVE-2013-0629","CVE-2013-0641","CVE-2014-0546","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-1010","CVE-2016-1019","CVE-2016-7855","CVE-2017-11292","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2018-0296","CVE-2018-15961","CVE-2018-4878","CVE-2018-4939","CVE-2019-0211","CVE-2019-0604","CVE-2019-0708","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-18935","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-0069","CVE-2020-0688","CVE-2020-0787","CVE-2020-12812","CVE-2020-1472","CVE-2020-25506","CVE-2020-3452","CVE-2020-3580","CVE-2020-5735","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-22893","CVE-2021-22894","CVE-2021-22899","CVE-2021-22900","CVE-2021-22986","CVE-2021-26085","CVE-2021-26855","CVE-2021-26857","CVE-2021-26858","CVE-2021-27065","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-29256","CVE-2021-31207","CVE-2021-32030","CVE-2021-33739","CVE-2021-34473","CVE-2021-35394","CVE-2021-36934","CVE-2021-4034","CVE-2021-40449","CVE-2021-40539","CVE-2021-41379","CVE-2021-42321","CVE-2021-44077","CVE-2021-44168","CVE-2021-44228","CVE-2021-44515","CVE-2021-45382","CVE-2022-1040","CVE-2022-1388","CVE-2022-20699","CVE-2022-20701","CVE-2022-20708","CVE-2022-21919","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-22954","CVE-2022-22960","CVE-2022-22963","CVE-2022-23131","CVE-2022-24086","CVE-2022-24521","CVE-2022-24682","CVE-2022-26138","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-29303","CVE-2022-3038","CVE-2022-3075","CVE-2022-37969","CVE-2022-41033","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-47966","CVE-2023-0386","CVE-2023-1389","CVE-2023-20109","CVE-2023-20118","CVE-2023-20198","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-2136","CVE-2023-21674","CVE-2023-22515","CVE-2023-22952","CVE-2023-23397","CVE-2023-2533","CVE-2023-26360","CVE-2023-27524","CVE-2023-27532","CVE-2023-27997","CVE-2023-28229","CVE-2023-28252","CVE-2023-2868","CVE-2023-32315","CVE-2023-33538","CVE-2023-34192","CVE-2023-34362","CVE-2023-35078","CVE-2023-3519","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-38950","CVE-2023-39780","CVE-2023-41179","CVE-2023-42793","CVE-2023-43770","CVE-2023-44221","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-49103","CVE-2023-4966","CVE-2023-5217","CVE-2023-5631","CVE-2023-6549","CVE-2023-7024","CVE-2024-0769","CVE-2024-11120","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20359","CVE-2024-20399","CVE-2024-20439","CVE-2024-21413","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-27443","CVE-2024-29059","CVE-2024-30051","CVE-2024-34102","CVE-2024-37085","CVE-2024-38080","CVE-2024-38112","CVE-2024-38475","CVE-2024-41710","CVE-2024-41713","CVE-2024-42009","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-48248","CVE-2024-4879","CVE-2024-4885","CVE-2024-49035","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-5217","CVE-2024-5274","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-55591","CVE-2024-57727","CVE-2024-57968","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-0411","CVE-2025-0994","CVE-2025-1976","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21480","CVE-2025-21590","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-24016","CVE-2025-24054","CVE-2025-24085","CVE-2025-24201","CVE-2025-24991","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27363","CVE-2025-2783","CVE-2025-30400","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-35939","CVE-2025-3928","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-48927","CVE-2025-48928","CVE-2025-49704","CVE-2025-49706","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6554","CVE-2025-6558"]},{"slug":"wineventlog-system","name":"WinEventLog:System","channels":[{"channel":"Changes to applicationhost.config or DLLs loaded by w3wp.exe","analytics":["AN0184"],"data_components":["DC0038"]},{"channel":"EventCode=1000","analytics":["AN0327"],"data_components":["DC0038"]},{"channel":"EventCode=1006","analytics":["AN0247","AN0841"],"data_components":["DC0042"]},{"channel":"EventCode=1006, 10001","analytics":["AN0342"],"data_components":["DC0042"]},{"channel":"EventCode=106, 200","analytics":["AN1118"],"data_components":["DC0005"]},{"channel":"EventCode=1341, 1342, 1020, 1063","analytics":["AN1290"],"data_components":["DC0038"]},{"channel":"EventCode=1502, 1503","analytics":["AN0199"],"data_components":["DC0029"]},{"channel":"EventCode=2003","analytics":["AN0446","AN0616","AN1410","AN1567"],"data_components":["DC0042"]},{"channel":"EventCode=4016, 5312","analytics":["AN1034"],"data_components":["DC0029"]},{"channel":"EventCode=5005 (WLAN), EventCode=302 (Bluetooth)","analytics":["AN0212"],"data_components":["DC0085"]},{"channel":"EventCode=7031, 7034","analytics":["AN0850"],"data_components":["DC0060"]},{"channel":"EventCode=7035","analytics":["AN0535","AN2038"],"data_components":["DC0041"]},{"channel":"EventCode=7036","analytics":["AN0061","AN0274","AN0868","AN2043"],"data_components":["DC0060"]},{"channel":"EventCode=7040","analytics":["AN1195"],"data_components":["DC0065"]},{"channel":"EventCode=7045","analytics":["AN0243","AN0324","AN0355","AN0462","AN0875","AN0886","AN0909","AN1061","AN1211","AN1366","AN1369","AN1620"],"data_components":["DC0060"]},{"channel":"EventCode=8001","analytics":["AN1531"],"data_components":["DC0082"]},{"channel":"Kernel-PnP 410/400 device install, disk added","analytics":["AN0185"],"data_components":["DC0042"]},{"channel":"Service stopped or RecoveryDisabled set via REAgentC","analytics":["AN0933"],"data_components":["DC0041"]},{"channel":"System shutdowns due to bugcheck (Event ID 1001) or watchdog timer expirations","analytics":["AN0584"],"data_components":["DC0018"]},{"channel":"Unexpected modification to lsass.exe or cryptdll.dll","analytics":["AN0757"],"data_components":["DC0061"]}],"data_components":["DC0005","DC0018","DC0029","DC0038","DC0041","DC0042","DC0060","DC0061","DC0065","DC0082","DC0085"],"analytics":["AN0061","AN0184","AN0185","AN0199","AN0212","AN0243","AN0247","AN0274","AN0324","AN0327","AN0342","AN0355","AN0446","AN0462","AN0535","AN0584","AN0616","AN0757","AN0841","AN0850","AN0868","AN0875","AN0886","AN0909","AN0933","AN1034","AN1061","AN1118","AN1195","AN1211","AN1290","AN1366","AN1369","AN1410","AN1531","AN1567","AN1620","AN2038","AN2043"],"techniques":["T1011","T1011.001","T1014","T1025","T1029","T1036","T1036.004","T1037.001","T1037.003","T1040","T1052","T1052.001","T1056.001","T1091","T1092","T1197","T1200","T1205.002","T1210","T1219","T1219.003","T1489","T1490","T1499","T1499.004","T1505.004","T1556.001","T1557.003","T1563.002","T1564.006","T1574.010","T1574.011","T1674","T1685","T1685.001","T1685.003","T1686.003","T1687"],"platforms":["Windows"],"kev_cves":["CVE-2015-3043","CVE-2018-4878","CVE-2020-5735","CVE-2021-32030","CVE-2021-35394","CVE-2021-41773","CVE-2021-42013","CVE-2022-1040","CVE-2022-26500","CVE-2022-26501","CVE-2023-0669","CVE-2023-20109","CVE-2023-36884","CVE-2023-44487","CVE-2023-6549","CVE-2024-40890","CVE-2024-40891","CVE-2024-50302","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-54085","CVE-2025-21391","CVE-2025-24985","CVE-2025-24991","CVE-2025-27363","CVE-2025-33053","CVE-2025-42599"]},{"slug":"azure-signinlogs","name":"azure:signinlogs","channels":[{"channel":"Abnormal sign-in from scripting tools (PowerShell, AADInternals)","analytics":["AN0131"],"data_components":["DC0067"]},{"channel":"Add certificate credential, Update certificate credential","analytics":["AN0674"],"data_components":["DC0066"]},{"channel":"ConsentGrant: Suspicious consent grants to non-approved or unknown applications","analytics":["AN0301"],"data_components":["DC0038"]},{"channel":"Failed MFA attempts, unusual conditional access triggers, login attempts from unexpected IP ranges","analytics":["AN0192"],"data_components":["DC0067"]},{"channel":"Failure Reason + UserPrincipalName","analytics":["AN1339"],"data_components":["DC0002"]},{"channel":"Graph API Query","analytics":["AN1616"],"data_components":["DC0083"]},{"channel":"Interactive/Non-Interactive Sign-In","analytics":["AN1087"],"data_components":["DC0002"]},{"channel":"InteractiveUser, NonInteractiveUser","analytics":["AN1350"],"data_components":["DC0067"]},{"channel":"InteractiveUser, ServicePrincipalSignIn","analytics":["AN1347"],"data_components":["DC0067"]},{"channel":"InteractiveUserLogin: Discovery behavior linked to privileged logins from atypical IP ranges","analytics":["AN1128"],"data_components":["DC0067"]},{"channel":"Login from newly created account","analytics":["AN0899"],"data_components":["DC0002"]},{"channel":"Modify Conditional Access Policy","analytics":["AN0544"],"data_components":["DC0038"]},{"channel":"Multiple MFA challenge requests without successful primary login","analytics":["AN0449"],"data_components":["DC0002"]},{"channel":"Operation=UserLogin","analytics":["AN0534"],"data_components":["DC0002"]},{"channel":"OperationName=SetDomainAuthentication OR Set-FederatedDomain","analytics":["AN0756"],"data_components":["DC0002"]},{"channel":"OperationName=SetDomainAuthentication OR Update-MsolFederatedDomain","analytics":["AN1260"],"data_components":["DC0064"]},{"channel":"Register PTA Agent or Modify AD FS trust","analytics":["AN0815"],"data_components":["DC0038"]},{"channel":"Reset password or download key from portal","analytics":["AN1157"],"data_components":["DC0002"]},{"channel":"SAML-based login with anomalous issuer or NotOnOrAfter lifetime","analytics":["AN0418"],"data_components":["DC0088"]},{"channel":"SAML/OIDC tokens issued without corresponding MFA or password validation","analytics":["AN0718"],"data_components":["DC0006"]},{"channel":"Sign-in activity","analytics":["AN1503"],"data_components":["DC0002"]},{"channel":"Sign-in logs","analytics":["AN1277","AN1524"],"data_components":["DC0002"]},{"channel":"Sign-in with unfamiliar location/device + portal navigation","analytics":["AN0809"],"data_components":["DC0002"]},{"channel":"SignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times","analytics":["AN0501"],"data_components":["DC0002"]},{"channel":"SigninSuccess","analytics":["AN1330"],"data_components":["DC0002"]},{"channel":"Success logs from high-risk accounts","analytics":["AN0295"],"data_components":["DC0002"]},{"channel":"Suspicious login to cloud mailbox system","analytics":["AN0132"],"data_components":["DC0067"]},{"channel":"TokenIssuanceStart, TokenIssuanceSuccess","analytics":["AN0956"],"data_components":["DC0007"]},{"channel":"TokenIssued, RefreshTokenUsed","analytics":["AN0527"],"data_components":["DC0007"]},{"channel":"TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events","analytics":["AN0496"],"data_components":["DC0002"]},{"channel":"Unusual Token Usage or Application Consent","analytics":["AN0642"],"data_components":["DC0002"]},{"channel":"UserLogin, ConditionalAccessPolicyEvaluated","analytics":["AN1380"],"data_components":["DC0067"]},{"channel":"status = failure","analytics":["AN1265"],"data_components":["DC0002"]},{"channel":"unusual role assumption or elevation path","analytics":["AN0978"],"data_components":["DC0010"]}],"data_components":["DC0002","DC0006","DC0007","DC0010","DC0038","DC0064","DC0066","DC0067","DC0083","DC0088"],"analytics":["AN0131","AN0132","AN0192","AN0295","AN0301","AN0418","AN0449","AN0496","AN0501","AN0527","AN0534","AN0544","AN0642","AN0674","AN0718","AN0756","AN0809","AN0815","AN0899","AN0956","AN0978","AN1087","AN1128","AN1157","AN1260","AN1265","AN1277","AN1330","AN1339","AN1347","AN1350","AN1380","AN1503","AN1524","AN1616"],"techniques":["T1078.004","T1087","T1087.003","T1087.004","T1110","T1110.001","T1110.002","T1110.003","T1110.004","T1114.002","T1119","T1136.003","T1189","T1199","T1212","T1213.002","T1484","T1484.002","T1526","T1530","T1538","T1548","T1550","T1550.001","T1552","T1556.006","T1556.007","T1566","T1566.002","T1606","T1606.002","T1621","T1649"],"platforms":["Identity Provider","Office Suite","SaaS","Windows"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2012-0767","CVE-2012-2034","CVE-2012-5054","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2020-0688","CVE-2020-1472","CVE-2020-5902","CVE-2021-40449","CVE-2021-44515","CVE-2022-1388","CVE-2022-22948","CVE-2022-23131","CVE-2022-34713","CVE-2022-41082","CVE-2022-41128","CVE-2023-22952","CVE-2023-2533","CVE-2023-27532","CVE-2023-36884","CVE-2023-43770","CVE-2023-44221","CVE-2023-49103","CVE-2023-7024","CVE-2024-11182","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20439","CVE-2024-21413","CVE-2024-21887","CVE-2024-27443","CVE-2024-38112","CVE-2024-42009","CVE-2024-4671","CVE-2024-49035","CVE-2024-4947","CVE-2024-5274","CVE-2024-53704","CVE-2025-24054","CVE-2025-24201","CVE-2025-2783","CVE-2025-48927","CVE-2025-48928","CVE-2025-5419","CVE-2025-6554","CVE-2025-6558"]},{"slug":"linux-osquery","name":"linux:osquery","channels":[{"channel":"/proc/*/maps access","analytics":["AN1494"],"data_components":["DC0055"]},{"channel":"Detection of bitwise operations or custom encryption functions in memory traces","analytics":["AN1214"],"data_components":["DC0020"]},{"channel":"Execution of binary resolved from $PATH not located in /usr/bin or /bin","analytics":["AN0010"],"data_components":["DC0032"]},{"channel":"Filesystem modifications to trusted paths","analytics":["AN0984"],"data_components":["DC0059"]},{"channel":"Listing of /etc/passwd and /etc/shadow metadata","analytics":["AN1078"],"data_components":["DC0013"]},{"channel":"New or modified kernel object files (.ko) within /lib/modules directory","analytics":["AN1243"],"data_components":["DC0061"]},{"channel":"None","analytics":["AN1532"],"data_components":["DC0055"]},{"channel":"Process State","analytics":["AN0096"],"data_components":["DC0035"]},{"channel":"Process execution with LD_PRELOAD or modified library path","analytics":["AN0610"],"data_components":["DC0032"]},{"channel":"Process linked with libcrypto.so making external connections","analytics":["AN0401"],"data_components":["DC0016"]},{"channel":"Processes linked with libssl or crypto libraries making outbound connections","analytics":["AN0760"],"data_components":["DC0032"]},{"channel":"Processes linked with libssl/libcrypto performing network activity","analytics":["AN1497"],"data_components":["DC0016"]},{"channel":"Read headers and detect MIME type mismatch","analytics":["AN0631"],"data_components":["DC0059"]},{"channel":"Write or modify .desktop file in XDG autostart path","analytics":["AN1096"],"data_components":["DC0059"]},{"channel":"child process invoking dynamic linker post-ptrace","analytics":["AN1241"],"data_components":["DC0032"]},{"channel":"crontab, systemd_timers","analytics":["AN0259"],"data_components":["DC0001"]},{"channel":"elf_info, hash, yara_matches","analytics":["AN0600"],"data_components":["DC0059"]},{"channel":"event-based","analytics":["AN0014","AN1463"],"data_components":["DC0059"]},{"channel":"execution of known firewall binaries","analytics":["AN0407"],"data_components":["DC0032"]},{"channel":"family=AF_PACKET or protocol raw; process name not in allowlist.","analytics":["AN0463"],"data_components":["DC0082"]},{"channel":"file_events","analytics":["AN0312","AN0356","AN0541","AN0645","AN0873","AN1062","AN1529","AN1627"],"data_components":["DC0001","DC0039","DC0059","DC0061"]},{"channel":"file_events.path","analytics":["AN0974"],"data_components":["DC0059"]},{"channel":"hardware_events","analytics":["AN1354"],"data_components":["DC0054"]},{"channel":"hash, elf_info, file_metadata","analytics":["AN0056"],"data_components":["DC0059"]},{"channel":"newly registered unit file with ExecStart pointing to unknown binary","analytics":["AN0701"],"data_components":["DC0060"]},{"channel":"process environment variables containing LD_PRELOAD","analytics":["AN1209"],"data_components":["DC0034"]},{"channel":"process execution events for permission modification utilities with command-line analysis","analytics":["AN0998"],"data_components":["DC0032"]},{"channel":"process listening or connecting on non-standard ports","analytics":["AN0634"],"data_components":["DC0032"]},{"channel":"process metadata mismatch between /proc and runtime attributes","analytics":["AN1196"],"data_components":["DC0034"]},{"channel":"process_events","analytics":["AN1306","AN1310","AN1418"],"data_components":["DC0032","DC0035"]},{"channel":"process_events.command_line","analytics":["AN1395"],"data_components":["DC0064"]},{"channel":"processes modifying environment variables related to history logging","analytics":["AN1555"],"data_components":["DC0032"]},{"channel":"scheduled/real-time","analytics":["AN0325"],"data_components":["DC0041"]},{"channel":"select: path LIKE '/dev/video%'","analytics":["AN0569"],"data_components":["DC0034"]},{"channel":"socat, ssh, or nc processes opening unexpected ports","analytics":["AN1484"],"data_components":["DC0032"]},{"channel":"socket_events","analytics":["AN1081"],"data_components":["DC0078"]},{"channel":"state=attached/debugged","analytics":["AN0579"],"data_components":["DC0034"]},{"channel":"unexpected termination of syslog or rsyslog processes","analytics":["AN0668"],"data_components":["DC0033"]}],"data_components":["DC0001","DC0013","DC0016","DC0020","DC0032","DC0033","DC0034","DC0035","DC0039","DC0041","DC0054","DC0055","DC0059","DC0060","DC0061","DC0064","DC0078","DC0082"],"analytics":["AN0010","AN0014","AN0056","AN0096","AN0259","AN0312","AN0325","AN0356","AN0401","AN0407","AN0463","AN0541","AN0569","AN0579","AN0600","AN0610","AN0631","AN0634","AN0645","AN0668","AN0701","AN0760","AN0873","AN0974","AN0984","AN0998","AN1062","AN1078","AN1081","AN1096","AN1196","AN1209","AN1214","AN1241","AN1243","AN1306","AN1310","AN1354","AN1395","AN1418","AN1463","AN1484","AN1494","AN1497","AN1529","AN1532","AN1555","AN1627"],"techniques":["T1003.005","T1011.001","T1014","T1027.001","T1027.005","T1027.006","T1027.008","T1027.009","T1027.010","T1027.011","T1036","T1036.002","T1036.003","T1036.004","T1036.005","T1036.008","T1036.010","T1037","T1053","T1053.006","T1055.008","T1055.009","T1055.014","T1057","T1059.004","T1070.006","T1114","T1120","T1125","T1205.002","T1222.002","T1480.001","T1543.002","T1547.006","T1547.013","T1560.003","T1564.013","T1571","T1572","T1573","T1573.001","T1573.002","T1574","T1574.006","T1574.007","T1686","T1690"],"platforms":["Linux"],"kev_cves":["CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-1010","CVE-2017-6742","CVE-2019-0708","CVE-2020-0688","CVE-2020-5735","CVE-2021-36380","CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2022-1040","CVE-2022-20699","CVE-2022-20700","CVE-2022-26500","CVE-2022-26501","CVE-2022-3038","CVE-2022-41073","CVE-2022-41328","CVE-2022-42475","CVE-2023-26360","CVE-2023-27997","CVE-2023-3519","CVE-2023-38035","CVE-2023-38831","CVE-2023-39780","CVE-2023-44221","CVE-2023-46604","CVE-2023-4966","CVE-2023-5217","CVE-2023-6549","CVE-2023-7024","CVE-2024-20353","CVE-2024-20359","CVE-2024-21762","CVE-2024-24919","CVE-2024-27443","CVE-2024-42009","CVE-2024-4577","CVE-2025-25257","CVE-2025-27363"]},{"slug":"esxi-shell","name":"esxi:shell","channels":[{"channel":"/root/.ash_history","analytics":["AN1172"],"data_components":["DC0064"]},{"channel":"/root/.ash_history or /etc/init.d/*","analytics":["AN0078"],"data_components":["DC0032"]},{"channel":"/var/log/shell.log","analytics":["AN0207","AN0395","AN0470"],"data_components":["DC0032","DC0040"]},{"channel":"/var/log/shell.log entries containing \"esxcli system clock get\"","analytics":["AN0433"],"data_components":["DC0064"]},{"channel":"/var/log/vmkernel.log, /var/log/vmkwarning.log","analytics":["AN0567"],"data_components":["DC0032"]},{"channel":"CLI usage logs","analytics":["AN0727"],"data_components":["DC0064"]},{"channel":"Command execution trace","analytics":["AN0754"],"data_components":["DC0064"]},{"channel":"Execution of cat, tail, grep targeting /var/log/vmkernel.log or /var/log/hostd.log","analytics":["AN0709"],"data_components":["DC0064"]},{"channel":"None","analytics":["AN0925","AN1018","AN1232","AN1640"],"data_components":["DC0029","DC0032","DC0064"]},{"channel":"Shell Access/Command Execution","analytics":["AN1043"],"data_components":["DC0064"]},{"channel":"Shell Execution","analytics":["AN0849"],"data_components":["DC0032"]},{"channel":"`esxcli software vib install` with `--force` or `--no-sig-check` from shell history or `shell.log`","analytics":["AN1475"],"data_components":["DC0064"]},{"channel":"admin command usage","analytics":["AN0660"],"data_components":["DC0061"]},{"channel":"base64 or gzip use within shell session","analytics":["AN0305"],"data_components":["DC0064"]},{"channel":"command IN (\"esxcli vm process list\", \"vim-cmd vmsvc/getallvms\")","analytics":["AN0572"],"data_components":["DC0064"]},{"channel":"commands containing base64, openssl enc -base64, xxd -p","analytics":["AN0348"],"data_components":["DC0032"]},{"channel":"commands containing long non-standard tokens or custom lookup tables","analytics":["AN0930"],"data_components":["DC0032"]},{"channel":"esxcli software vib list","analytics":["AN1104"],"data_components":["DC0064"]},{"channel":"esxcli system shutdown or reboot invoked","analytics":["AN1541"],"data_components":["DC0064"]},{"channel":"esxcli system syslog config set --loghost='' or stopping hostd service","analytics":["AN0890"],"data_components":["DC0064"]},{"channel":"esxcli system syslog config set/reload, services.sh restart/stop","analytics":["AN2044"],"data_components":["DC0064"]},{"channel":"file write or edit","analytics":["AN0353"],"data_components":["DC0061"]},{"channel":"interactive shell","analytics":["AN0098"],"data_components":["DC0064"]},{"channel":"invoked remote scripts (esxcli)","analytics":["AN0197"],"data_components":["DC0064"]},{"channel":"mv, rename, or chmod commands moving VM files into hidden directories","analytics":["AN1387"],"data_components":["DC0064"]},{"channel":"openssl|tar|dd","analytics":["AN0605"],"data_components":["DC0064"]},{"channel":"scripts or binaries with misleading names","analytics":["AN0359"],"data_components":["DC0064"]},{"channel":"shell command execution for chmod, chown, or file permission modification on VMFS or system files","analytics":["AN0837"],"data_components":["DC0064"]},{"channel":"shell command execution for system discovery (vim-cmd, esxcli, vmware-cmd) targeting VM inventory and host configuration","analytics":["AN1554"],"data_components":["DC0064"]},{"channel":"shell history","analytics":["AN0116"],"data_components":["DC0040"]},{"channel":"snapshot create/copy, esxcli","analytics":["AN0044"],"data_components":["DC0064"]},{"channel":"unset HISTFILE or HISTFILESIZE modifications","analytics":["AN1558"],"data_components":["DC0064"]}],"data_components":["DC0029","DC0032","DC0040","DC0061","DC0064"],"analytics":["AN0044","AN0078","AN0098","AN0116","AN0197","AN0207","AN0305","AN0348","AN0353","AN0359","AN0395","AN0433","AN0470","AN0567","AN0572","AN0605","AN0660","AN0709","AN0727","AN0754","AN0837","AN0849","AN0890","AN0925","AN0930","AN1018","AN1043","AN1104","AN1172","AN1232","AN1387","AN1475","AN1541","AN1554","AN1558","AN1640","AN2044"],"techniques":["T1016.001","T1021","T1021.004","T1036","T1037.004","T1057","T1070.003","T1070.004","T1070.009","T1071.001","T1071.002","T1074","T1074.001","T1074.002","T1083","T1087.001","T1090","T1090.001","T1090.002","T1090.004","T1098.004","T1124","T1132","T1132.001","T1132.002","T1222","T1480","T1486","T1505.006","T1518","T1529","T1564","T1654","T1673","T1685","T1690"],"platforms":["ESXi"],"kev_cves":["CVE-2009-3960","CVE-2009-4324","CVE-2015-3113","CVE-2015-5119","CVE-2015-8651","CVE-2016-1019","CVE-2017-12637","CVE-2019-11510","CVE-2019-11634","CVE-2019-19781","CVE-2019-3396","CVE-2020-1472","CVE-2020-5902","CVE-2021-22017","CVE-2021-22986","CVE-2021-26855","CVE-2021-34473","CVE-2021-35394","CVE-2021-40449","CVE-2021-40539","CVE-2021-42258","CVE-2021-44077","CVE-2021-44228","CVE-2021-45046","CVE-2022-22947","CVE-2022-22960","CVE-2022-26500","CVE-2022-26501","CVE-2022-40684","CVE-2022-42475","CVE-2023-0669","CVE-2023-22952","CVE-2023-26360","CVE-2023-27532","CVE-2023-28252","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-39780","CVE-2023-40044","CVE-2024-4577","CVE-2024-4978","CVE-2024-53704","CVE-2024-55591","CVE-2025-32433","CVE-2025-32756","CVE-2025-54309"]},{"slug":"esxi-hostd","name":"esxi:hostd","channels":[{"channel":"/var/log/hostd.log","analytics":["AN0175","AN0593"],"data_components":["DC0064","DC0088"]},{"channel":"/var/log/hostd.log API calls reading/altering time/ntp settings","analytics":["AN0433"],"data_components":["DC0034"]},{"channel":"/var/log/hostd.log anomalies (faults, crashes, restarts) around inbound connections","analytics":["AN0224"],"data_components":["DC0038"]},{"channel":"CLI network calls","analytics":["AN0640","AN1602"],"data_components":["DC0078"]},{"channel":"Command Execution","analytics":["AN1074"],"data_components":["DC0064"]},{"channel":"Execution of '/bin/vmx' or modifications to '/etc/rc.local.d/local.sh'","analytics":["AN0912"],"data_components":["DC0064"]},{"channel":"Guest Operations API invocation: StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, InitiateFileTransferFromGuest","analytics":["AN0646"],"data_components":["DC0038"]},{"channel":"Host daemon command log entries related to vib enumeration","analytics":["AN1104"],"data_components":["DC0038"]},{"channel":"Keywords: 'Backtrace','Signal 11','PANIC','hostd restarted','assert' or 'Service terminated unexpectedly' in /var/log/hostd.log, /var/log/vmkernel.log, /var/log/syslog.log.","analytics":["AN0329"],"data_components":["DC0038"]},{"channel":"Log entries indicating VM powered off or forcibly terminated","analytics":["AN0064"],"data_components":["DC0033"]},{"channel":"New extension/module install with unknown vendor ID","analytics":["AN1510"],"data_components":["DC0038"]},{"channel":"None","analytics":["AN0562","AN1586"],"data_components":["DC0064"]},{"channel":"Powering off or restarting host","analytics":["AN1541"],"data_components":["DC0018"]},{"channel":"Remote access API calls and file uploads","analytics":["AN1068"],"data_components":["DC0021"]},{"channel":"Service events","analytics":["AN0987"],"data_components":["DC0041"]},{"channel":"Service initiated connections","analytics":["AN0654"],"data_components":["DC0082"]},{"channel":"Service-Based Network Connection","analytics":["AN1297"],"data_components":["DC0082"]},{"channel":"Stop VM or disable service events via vim-cmd","analytics":["AN0064"],"data_components":["DC0041"]},{"channel":"System service interactions","analytics":["AN0033"],"data_components":["DC0082"]},{"channel":"binary or module replacement event","analytics":["AN0952"],"data_components":["DC0061"]},{"channel":"boot","analytics":["AN0314"],"data_components":["DC0061"]},{"channel":"command execution","analytics":["AN0168"],"data_components":["DC0064"]},{"channel":"command log","analytics":["AN0906"],"data_components":["DC0064"]},{"channel":"datastore file access","analytics":["AN0439","AN0898","AN1574"],"data_components":["DC0055"]},{"channel":"datastore/log file access","analytics":["AN0790"],"data_components":["DC0055"]},{"channel":"esxcli network firewall set commands","analytics":["AN0409"],"data_components":["DC0064"]},{"channel":"esxcli system syslog config set or reload","analytics":["AN0670"],"data_components":["DC0064"]},{"channel":"event stream","analytics":["AN0426","AN1416"],"data_components":["DC0064"]},{"channel":"execution + payload hints","analytics":["AN1392"],"data_components":["DC0064"]},{"channel":"execution of esxcli with args matching 'storage', 'filesystem', 'core device list'","analytics":["AN0539"],"data_components":["DC0032"]},{"channel":"file copy or datastore upload via HTTPS","analytics":["AN1515"],"data_components":["DC0055"]},{"channel":"host daemon events related to VM operations and configuration queries during reconnaissance","analytics":["AN1554"],"data_components":["DC0032"]},{"channel":"host daemon events related to file or VM permission changes","analytics":["AN0837"],"data_components":["DC0059"]},{"channel":"logline inspection","analytics":["AN0371"],"data_components":["DC0064"]},{"channel":"method=RemoveUser or esxcli system account remove invocation","analytics":["AN0337"],"data_components":["DC0009"]},{"channel":"modification of config files or shell command execution","analytics":["AN0232"],"data_components":["DC0064"]},{"channel":"modification of crontab or local.sh entries","analytics":["AN0807"],"data_components":["DC0061"]},{"channel":"process","analytics":["AN1018"],"data_components":["DC0032"]},{"channel":"process execution across cloud VM","analytics":["AN0198"],"data_components":["DC0032"]},{"channel":"read: Access to sensitive log files by non-admin users","analytics":["AN0709"],"data_components":["DC0055"]},{"channel":"registers services with legitimate-sounding names","analytics":["AN0359"],"data_components":["DC0041"]},{"channel":"rm, clearlogs, logrotate","analytics":["AN0524"],"data_components":["DC0040"]},{"channel":"scp/ssh used to move file across hosts","analytics":["AN0519"],"data_components":["DC0064"]},{"channel":"service state change","analytics":["AN2044"],"data_components":["DC0065"]},{"channel":"shell access or job registration","analytics":["AN0262"],"data_components":["DC0064"]},{"channel":"snapshot.removeall or snapshot file deletion","analytics":["AN0935"],"data_components":["DC0049"]},{"channel":"task creation events","analytics":["AN0987"],"data_components":["DC0001"]},{"channel":"unexpected script invocations producing long encoded strings","analytics":["AN0930"],"data_components":["DC0038"]},{"channel":"unexpected script/command invocations via hostd","analytics":["AN0348"],"data_components":["DC0038"]},{"channel":"vSphere API calls modifying firewall settings","analytics":["AN0409"],"data_components":["DC0051"]},{"channel":"vSphere File API Access","analytics":["AN1043"],"data_components":["DC0055"]}],"data_components":["DC0001","DC0009","DC0018","DC0021","DC0032","DC0033","DC0034","DC0038","DC0040","DC0041","DC0049","DC0051","DC0055","DC0059","DC0061","DC0064","DC0065","DC0078","DC0082","DC0088"],"analytics":["AN0033","AN0064","AN0168","AN0175","AN0198","AN0224","AN0232","AN0262","AN0314","AN0329","AN0337","AN0348","AN0359","AN0371","AN0409","AN0426","AN0433","AN0439","AN0519","AN0524","AN0539","AN0562","AN0593","AN0640","AN0646","AN0654","AN0670","AN0709","AN0790","AN0807","AN0837","AN0898","AN0906","AN0912","AN0930","AN0935","AN0952","AN0987","AN1018","AN1043","AN1068","AN1074","AN1104","AN1297","AN1392","AN1416","AN1510","AN1515","AN1541","AN1554","AN1574","AN1586","AN1602","AN2044"],"techniques":["T1001.001","T1001.002","T1001.003","T1005","T1016","T1016.001","T1018","T1027","T1036","T1036.005","T1037","T1048","T1048.001","T1048.002","T1048.003","T1049","T1053","T1053.003","T1059.006","T1070","T1074.002","T1078.002","T1083","T1102.003","T1104","T1105","T1124","T1132.001","T1132.002","T1190","T1210","T1222","T1480","T1489","T1490","T1491.001","T1505","T1518","T1529","T1531","T1554","T1564.006","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1570","T1654","T1675","T1680","T1685","T1686"],"platforms":["ESXi","IaaS"],"kev_cves":["CVE-2009-3960","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2012-0754","CVE-2012-1535","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0641","CVE-2014-6271","CVE-2014-7169","CVE-2015-5119","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1019","CVE-2016-4117","CVE-2016-4437","CVE-2017-11292","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-0296","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-15982","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2019-19781","CVE-2019-5591","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-3452","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26855","CVE-2021-26858","CVE-2021-27065","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-29256","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40449","CVE-2021-40539","CVE-2021-40655","CVE-2021-41773","CVE-2021-42013","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22960","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-30190","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-41082","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-1389","CVE-2023-20198","CVE-2023-20867","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-2868","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-4966","CVE-2023-7101","CVE-2024-0769","CVE-2024-11182","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20359","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-41713","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-4978","CVE-2024-50302","CVE-2024-5217","CVE-2024-53150","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0111","CVE-2025-0282","CVE-2025-1316","CVE-2025-21391","CVE-2025-21418","CVE-2025-22226","CVE-2025-22457","CVE-2025-23006","CVE-2025-24991","CVE-2025-25257","CVE-2025-31200","CVE-2025-31201","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-48927","CVE-2025-48928","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-54309","CVE-2025-5777"]},{"slug":"aws-cloudtrail","name":"AWS:CloudTrail","channels":[{"channel":"AWS ConsoleLogin, StartSession","analytics":["AN0753"],"data_components":["DC0067"]},{"channel":"AWS IAM: ListUsers, ListRoles","analytics":["AN1088"],"data_components":["DC0002"]},{"channel":"AssumeRole","analytics":["AN0417","AN0958","AN0960","AN1328"],"data_components":["DC0013"]},{"channel":"AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests","analytics":["AN0450"],"data_components":["DC0002"]},{"channel":"AssumeRole, GetFederationToken API calls by unusual or new entities","analytics":["AN0717"],"data_components":["DC0006"]},{"channel":"AssumeRole, GetFederationToken, GetSessionToken","analytics":["AN0526"],"data_components":["DC0007"]},{"channel":"AssumeRole,AssumeRoleWithSAML,AssumeRoleWithWebIdentity","analytics":["AN1348"],"data_components":["DC0067"]},{"channel":"AssumeRole: Discovery actions tied to assumed identities outside of normal context","analytics":["AN1127"],"data_components":["DC0013"]},{"channel":"AssumeRoleWithSAML","analytics":["AN0419"],"data_components":["DC0007"]},{"channel":"AssumeRoleWithWebIdentity","analytics":["AN0530"],"data_components":["DC0002"]},{"channel":"AttachUserPolicy","analytics":["AN0900","AN1608"],"data_components":["DC0010"]},{"channel":"AttachUserPolicy, CreatePolicyVersion, PutRolePolicy","analytics":["AN0771"],"data_components":["DC0010"]},{"channel":"AuthorizeSecurityGroupIngress","analytics":["AN0492","AN2041"],"data_components":["DC0051"]},{"channel":"ConsoleLogin","analytics":["AN0201","AN0808"],"data_components":["DC0067"]},{"channel":"ConsoleLogin or AssumeRole","analytics":["AN1285"],"data_components":["DC0002"]},{"channel":"ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser","analytics":["AN1504"],"data_components":["DC0002"]},{"channel":"ConsoleLogin, AssumeRole, ListResources","analytics":["AN0017"],"data_components":["DC0067"]},{"channel":"ConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise","analytics":["AN0501"],"data_components":["DC0067"]},{"channel":"CopySnapshot","analytics":["AN1580"],"data_components":["DC0062"]},{"channel":"Create egress rule allowing UDP to port 53, 123, 11211","analytics":["AN1143"],"data_components":["DC0051"]},{"channel":"CreateAccessKey, ImportKeyPair, CreateLoginProfile, CreateKeyPair","analytics":["AN1470"],"data_components":["DC0087"]},{"channel":"CreateBucket","analytics":["AN0690"],"data_components":["DC0024"]},{"channel":"CreateFunction","analytics":["AN0027"],"data_components":["DC0069"]},{"channel":"CreateFunction / UpdateFunctionConfiguration: Function creation, role assignment, or configuration change events","analytics":["AN1053"],"data_components":["DC0069"]},{"channel":"CreatePod: Programmatic creation of new pod resources using container images not seen before in the environment","analytics":["AN0233"],"data_components":["DC0019"]},{"channel":"CreateSnapshot","analytics":["AN0861","AN1187","AN1580"],"data_components":["DC0057"]},{"channel":"CreateTrafficMirrorSession / ModifyTrafficMirrorTarget","analytics":["AN0878"],"data_components":["DC0069"]},{"channel":"CreateTrafficMirrorSession or ModifyTrafficMirrorTarget","analytics":["AN1131"],"data_components":["DC0078"]},{"channel":"CreateUser","analytics":["AN0900","AN1608"],"data_components":["DC0014"]},{"channel":"CreateUser|AttachRolePolicy|CreateAccessKey|UpdateAssumeRolePolicy|CreateLoginProfile","analytics":["AN1348"],"data_components":["DC0038"]},{"channel":"CreateVolume","analytics":["AN0861"],"data_components":["DC0097"]},{"channel":"Decrypt","analytics":["AN1201"],"data_components":["DC0021"]},{"channel":"Delete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls","analytics":["AN1372"],"data_components":["DC0069"]},{"channel":"DeleteBucket, DeleteDBCluster, DeleteSnapshot, TerminateInstances","analytics":["AN0414","AN0937"],"data_components":["DC0022"]},{"channel":"DeleteSnapshot","analytics":["AN0861","AN0937"],"data_components":["DC0049"]},{"channel":"DeleteVolume, ModifyVolume","analytics":["AN0861"],"data_components":["DC0098"]},{"channel":"Describe* or List* API calls","analytics":["AN0908"],"data_components":["DC0021"]},{"channel":"DescribeDBInstances","analytics":["AN0481"],"data_components":["DC0075"]},{"channel":"DescribeInstances","analytics":["AN0234","AN0481","AN1242"],"data_components":["DC0086"]},{"channel":"DescribeInstances, DescribeServices, ListFunctions: High frequency enumeration calls or unusual user agents performing discovery","analytics":["AN1127"],"data_components":["DC0083"]},{"channel":"DescribeInstances, GetConsoleOutput, DescribeImages","analytics":["AN1456"],"data_components":["DC0075"]},{"channel":"DescribeSnapshots","analytics":["AN1187"],"data_components":["DC0062"]},{"channel":"DescribeUsers / ListUsers / GetUser","analytics":["AN1615"],"data_components":["DC0083"]},{"channel":"GetAccountPasswordPolicy","analytics":["AN0458"],"data_components":["DC0013"]},{"channel":"GetCallerIdentity","analytics":["AN0960"],"data_components":["DC0007"]},{"channel":"GetInstanceIdentityDocument","analytics":["AN0001"],"data_components":["DC0070"]},{"channel":"GetInstanceIdentityDocument or IMDSv2 token requests","analytics":["AN1424"],"data_components":["DC0083"]},{"channel":"GetLogEvents: High frequency log exports from CloudWatch or equivalent services","analytics":["AN0708"],"data_components":["DC0064"]},{"channel":"GetMetadata, DescribeInstanceIdentity","analytics":["AN0122"],"data_components":["DC0021"]},{"channel":"GetObject, CopyObject","analytics":["AN0043","AN0198","AN0370","AN0666","AN1328","AN1594","AN1625"],"data_components":["DC0025"]},{"channel":"GetSecretValue","analytics":["AN0366","AN1157","AN1201"],"data_components":["DC0070","DC0083"]},{"channel":"GetSessionToken, AssumeRoleWithWebIdentity","analytics":["AN0483"],"data_components":["DC0007"]},{"channel":"Ingress rule creation or modification for security group","analytics":["AN1188"],"data_components":["DC0051"]},{"channel":"InvokeFunction","analytics":["AN0027","AN1168"],"data_components":["DC0064","DC0070"]},{"channel":"InvokeFunction: Unexpected or repeated invocation of functions not tied to known workflows","analytics":["AN1053"],"data_components":["DC0038"]},{"channel":"LeaveOrganization: API calls severing accounts from AWS Organizations","analytics":["AN0442"],"data_components":["DC0069"]},{"channel":"ListBuckets","analytics":["AN0481","AN1625"],"data_components":["DC0017"]},{"channel":"ListGroups, ListAttachedRolePolicies","analytics":["AN0695"],"data_components":["DC0099"]},{"channel":"ListObjectsV2","analytics":["AN1594"],"data_components":["DC0017"]},{"channel":"ModifyImageAttribute","analytics":["AN0947"],"data_components":["DC0036"]},{"channel":"ModifyInstanceAttribute","analytics":["AN2041"],"data_components":["DC0073"]},{"channel":"ModifySnapshotAttribute","analytics":["AN0861","AN1580"],"data_components":["DC0058"]},{"channel":"ModifyVolume","analytics":["AN0861"],"data_components":["DC0092"]},{"channel":"PassRole","analytics":["AN1105"],"data_components":["DC0013"]},{"channel":"Post-authentication metadata enumeration from GUI session","analytics":["AN0808"],"data_components":["DC0027"]},{"channel":"PutBucketLifecycle, PutLifecycleConfiguration, SetBucketLifecycle, storage.buckets.update","analytics":["AN0117"],"data_components":["DC0023"]},{"channel":"PutBucketPolicy","analytics":["AN1580"],"data_components":["DC0023"]},{"channel":"PutIdentityPolicy","analytics":["AN0417"],"data_components":["DC0069"]},{"channel":"PutObject","analytics":["AN1625"],"data_components":["DC0039"]},{"channel":"PutObject (with SSE-C), UploadPart (SSE-C)","analytics":["AN0606"],"data_components":["DC0023"]},{"channel":"PutObject: S3 writes with .sql/.csv extension by same identity or within 5 min of DB access","analytics":["AN0679"],"data_components":["DC0025"]},{"channel":"PutUserPolicy, PutGroupPolicy, PutRolePolicy, CreatePolicyVersion","analytics":["AN0087"],"data_components":["DC0069"]},{"channel":"RegisterImage","analytics":["AN0947"],"data_components":["DC0015"]},{"channel":"Removal of restrictive egress rules from a security group","analytics":["AN1188"],"data_components":["DC0043"]},{"channel":"RequestServiceQuotaIncrease","analytics":["AN1356"],"data_components":["DC0069"]},{"channel":"RevertSnapshot","analytics":["AN0953"],"data_components":["DC0073"]},{"channel":"RunInstances","analytics":["AN0690","AN0692","AN0744","AN0861","AN0947","AN1242","AN1493"],"data_components":["DC0080"]},{"channel":"RunInstances,CreateImage","analytics":["AN1318"],"data_components":["DC0076"]},{"channel":"SSM RunCommand","analytics":["AN0626"],"data_components":["DC0064"]},{"channel":"SendCommand, StartSession, ExecuteCommand: Unexpected AWS Systems Manager command execution targeting EC2 instances","analytics":["AN1502"],"data_components":["DC0064"]},{"channel":"SendEmail","analytics":["AN0417"],"data_components":["DC0038"]},{"channel":"SendSSHPublicKey, StartSession (SSM), EC2InstanceConnect","analytics":["AN0594"],"data_components":["DC0067"]},{"channel":"SessionToken used without preceding MFA or login event","analytics":["AN0201"],"data_components":["DC0007"]},{"channel":"StartInstances","analytics":["AN0084","AN0587","AN0953","AN1318"],"data_components":["DC0080"]},{"channel":"Stop logging for an existing CloudTrail","analytics":["AN0801"],"data_components":["DC0090"]},{"channel":"StopInstances","analytics":["AN0953"],"data_components":["DC0089"]},{"channel":"StopLogging, DeleteTrail, UpdateTrail: API calls that disable or modify logging services","analytics":["AN1636"],"data_components":["DC0038"]},{"channel":"StopLogging, DeleteTrail, or DisableSecurityService","analytics":["AN0891","AN2041"],"data_components":["DC0090"]},{"channel":"Temporary security credentials used to authenticate into management console or APIs","analytics":["AN0717"],"data_components":["DC0067"]},{"channel":"TerminateInstances","analytics":["AN0234","AN0853","AN0861"],"data_components":["DC0089"]},{"channel":"UpdateAccountPasswordPolicy","analytics":["AN0291"],"data_components":["DC0069"]},{"channel":"UpdateFederationSettings or RegisterHybridConnector","analytics":["AN0816"],"data_components":["DC0069"]},{"channel":"UpdateIdentityPolicy or DisableMFA","analytics":["AN0545"],"data_components":["DC0069"]},{"channel":"UpdateLoginProfile","analytics":["AN0291"],"data_components":["DC0010"]},{"channel":"Use of temporary credentials issued from IMDS access","analytics":["AN1424"],"data_components":["DC0069"]},{"channel":"Web console logins using session cookies without corresponding MFA event","analytics":["AN0483"],"data_components":["DC0067"]},{"channel":"command-line execution invoking credential enumeration","analytics":["AN0860"],"data_components":["DC0064"]},{"channel":"cross-account or unexpected assume role","analytics":["AN0979"],"data_components":["DC0034"]},{"channel":"eventName: RunInstances, CreateUser, PutRolePolicy, InvokeCommand","analytics":["AN0215"],"data_components":["DC0064"]},{"channel":"eventName=ConsoleLogin | eventType=AwsConsoleSignIn","analytics":["AN1270"],"data_components":["DC0002"]},{"channel":"rds:ExecuteStatement: Large data access via RDS or Aurora with unknown session context","analytics":["AN0679"],"data_components":["DC0070"]},{"channel":"role privilege expansion detected","analytics":["AN0979"],"data_components":["DC0010"]},{"channel":"ssm:GetCommandInvocation","analytics":["AN1103"],"data_components":["DC0064"]},{"channel":"ssm:ListInventoryEntries","analytics":["AN1103"],"data_components":["DC0083"]},{"channel":"sts:GetFederationToken","analytics":["AN0526"],"data_components":["DC0002"]},{"channel":"sudden role assumption after credential file access","analytics":["AN0860"],"data_components":["DC0067"]}],"data_components":["DC0002","DC0006","DC0007","DC0010","DC0013","DC0014","DC0015","DC0017","DC0019","DC0021","DC0022","DC0023","DC0024","DC0025","DC0027","DC0034","DC0036","DC0038","DC0039","DC0043","DC0049","DC0051","DC0057","DC0058","DC0062","DC0064","DC0067","DC0069","DC0070","DC0073","DC0075","DC0076","DC0078","DC0080","DC0083","DC0086","DC0087","DC0089","DC0090","DC0092","DC0097","DC0098","DC0099"],"analytics":["AN0001","AN0017","AN0027","AN0043","AN0084","AN0087","AN0117","AN0122","AN0198","AN0201","AN0215","AN0233","AN0234","AN0291","AN0366","AN0370","AN0414","AN0417","AN0419","AN0442","AN0450","AN0458","AN0481","AN0483","AN0492","AN0501","AN0526","AN0530","AN0545","AN0587","AN0594","AN0606","AN0626","AN0666","AN0679","AN0690","AN0692","AN0695","AN0708","AN0717","AN0744","AN0753","AN0771","AN0801","AN0808","AN0816","AN0853","AN0860","AN0861","AN0878","AN0891","AN0900","AN0908","AN0937","AN0947","AN0953","AN0958","AN0960","AN0979","AN1053","AN1088","AN1103","AN1105","AN1127","AN1131","AN1143","AN1157","AN1168","AN1187","AN1188","AN1201","AN1242","AN1270","AN1285","AN1318","AN1328","AN1348","AN1356","AN1372","AN1424","AN1456","AN1470","AN1493","AN1502","AN1504","AN1580","AN1594","AN1608","AN1615","AN1625","AN1636","AN2041"],"techniques":["T1020.001","T1021","T1021.007","T1021.008","T1040","T1048","T1049","T1059.009","T1059.013","T1069.003","T1072","T1074","T1074.002","T1078.001","T1078.004","T1082","T1087","T1087.004","T1098.001","T1098.003","T1110.004","T1136","T1136.003","T1189","T1199","T1201","T1204","T1204.003","T1211","T1213.006","T1485","T1485.001","T1486","T1490","T1491","T1491.002","T1496","T1496.001","T1496.002","T1496.004","T1498.002","T1499","T1499.002","T1499.003","T1499.004","T1518","T1525","T1526","T1528","T1530","T1535","T1537","T1538","T1546","T1548","T1548.005","T1550","T1550.001","T1550.004","T1552","T1552.001","T1552.005","T1555","T1555.006","T1556","T1556.006","T1556.007","T1556.009","T1578","T1578.001","T1578.002","T1578.003","T1578.004","T1578.005","T1580","T1606","T1606.001","T1606.002","T1614","T1619","T1621","T1648","T1651","T1654","T1666","T1685","T1685.002","T1686.001","T1687"],"platforms":["Containers","IaaS","Identity Provider","SaaS","Windows"],"kev_cves":["CVE-2009-3960","CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2013-0641","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2017-12637","CVE-2017-6742","CVE-2017-9822","CVE-2018-11776","CVE-2018-15961","CVE-2018-7600","CVE-2019-11510","CVE-2019-11634","CVE-2019-1653","CVE-2019-18935","CVE-2020-12812","CVE-2020-1472","CVE-2020-5735","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2021-22205","CVE-2021-22986","CVE-2021-26084","CVE-2021-32030","CVE-2021-34473","CVE-2021-35394","CVE-2021-39226","CVE-2021-40449","CVE-2021-40539","CVE-2021-42258","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-45046","CVE-2021-45382","CVE-2022-1040","CVE-2022-1388","CVE-2022-21999","CVE-2022-22947","CVE-2022-23131","CVE-2022-26138","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-29464","CVE-2022-41082","CVE-2022-41328","CVE-2023-0669","CVE-2023-1389","CVE-2023-20109","CVE-2023-20198","CVE-2023-22515","CVE-2023-22527","CVE-2023-22952","CVE-2023-27532","CVE-2023-27997","CVE-2023-28252","CVE-2023-32315","CVE-2023-34362","CVE-2023-35078","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46805","CVE-2023-47565","CVE-2023-49103","CVE-2023-49897","CVE-2023-6549","CVE-2023-7024","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20439","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-38112","CVE-2024-38475","CVE-2024-4671","CVE-2024-49035","CVE-2024-4947","CVE-2024-5274","CVE-2024-53704","CVE-2024-54085","CVE-2024-55591","CVE-2024-57727","CVE-2025-21391","CVE-2025-24054","CVE-2025-24201","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-27363","CVE-2025-2783","CVE-2025-31161","CVE-2025-42599","CVE-2025-4632","CVE-2025-48927","CVE-2025-48928","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6554","CVE-2025-6558"]},{"slug":"wineventlog-powershell","name":"WinEventLog:PowerShell","channels":[{"channel":"CmdletName: Get-Recipient, Get-User","analytics":["AN1089"],"data_components":["DC0064"]},{"channel":"CommandLine=copy-item or robocopy from UNC path","analytics":["AN0194"],"data_components":["DC0064"]},{"channel":"EventCode=400, 403","analytics":["AN1252"],"data_components":["DC0034"]},{"channel":"EventCode=4103, 4104, 4105, 4106","analytics":["AN0037","AN0089","AN0131","AN0152","AN0182","AN0254","AN0271","AN0274","AN0286","AN0345","AN0363","AN0388","AN0392","AN0430","AN0455","AN0469","AN0472","AN0507","AN0513","AN0551","AN0559","AN0589","AN0622","AN0641","AN0737","AN0834","AN0903","AN0927","AN0932","AN0962","AN1015","AN1025","AN1028","AN1177","AN1207","AN1220","AN1252","AN1280","AN1288","AN1305","AN1309","AN1325","AN1440","AN1448","AN1452","AN1461","AN1464","AN1551","AN1557","AN1567","AN1589","AN1621","AN2030","AN2063"],"data_components":["DC0029","DC0064"]},{"channel":"Exchange Cmdlets","analytics":["AN0740"],"data_components":["DC0064"]},{"channel":"Execution of 'Get-WmiObject Win32_Product' or similar PowerShell cmdlets","analytics":["AN1100"],"data_components":["DC0064"]},{"channel":"Execution of Microsoft script to enumerate custom forms in Outlook mailbox","analytics":["AN0085"],"data_components":["DC0064"]},{"channel":"Execution of PowerShell script to enumerate or remove malicious Home Page folder config","analytics":["AN0502"],"data_components":["DC0064"]},{"channel":"Execution of PowerShell without -NoProfile flag","analytics":["AN1245"],"data_components":["DC0064"]},{"channel":"Get-ADTrust|GetAllTrustRelationships","analytics":["AN0016"],"data_components":["DC0064"]},{"channel":"PowerShell launched from outlook.exe or triggered without user invocation","analytics":["AN0263"],"data_components":["DC0064"]},{"channel":"Scripts with references to XML parsing, AES decryption, or gpprefdecrypt logic","analytics":["AN1075"],"data_components":["DC0029"]},{"channel":"Set-ADUser or Set-ADAuthenticationPolicy with MFA attributes disabled","analytics":["AN0543"],"data_components":["DC0029"]}],"data_components":["DC0029","DC0034","DC0064"],"analytics":["AN0016","AN0037","AN0085","AN0089","AN0131","AN0152","AN0182","AN0194","AN0254","AN0263","AN0271","AN0274","AN0286","AN0345","AN0363","AN0388","AN0392","AN0430","AN0455","AN0469","AN0472","AN0502","AN0507","AN0513","AN0543","AN0551","AN0559","AN0589","AN0622","AN0641","AN0737","AN0740","AN0834","AN0903","AN0927","AN0932","AN0962","AN1015","AN1025","AN1028","AN1075","AN1089","AN1100","AN1177","AN1207","AN1220","AN1245","AN1252","AN1280","AN1288","AN1305","AN1309","AN1325","AN1440","AN1448","AN1452","AN1461","AN1464","AN1551","AN1557","AN1567","AN1589","AN1621","AN2030","AN2063"],"techniques":["T1007","T1010","T1012","T1016","T1016.001","T1016.002","T1027.018","T1033","T1036.001","T1036.002","T1049","T1056.002","T1059.001","T1069","T1069.002","T1070.003","T1070.004","T1070.005","T1070.008","T1074.002","T1082","T1087.002","T1087.003","T1087.004","T1114","T1114.002","T1114.003","T1124","T1132.001","T1132.002","T1135","T1137.003","T1137.004","T1137.005","T1197","T1201","T1204.004","T1205","T1216","T1216.001","T1216.002","T1217","T1218.003","T1218.004","T1218.009","T1218.013","T1218.014","T1222","T1222.001","T1480","T1480.001","T1482","T1505.002","T1518","T1546.013","T1552.006","T1556.005","T1556.006","T1564.008","T1564.011","T1615","T1674","T1679","T1690"],"platforms":["Office Suite","Windows"],"kev_cves":["CVE-2012-0767","CVE-2019-1653","CVE-2020-0688","CVE-2020-1472","CVE-2020-3580","CVE-2020-5902","CVE-2020-8195","CVE-2020-8196","CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2021-44515","CVE-2022-22960","CVE-2022-41082","CVE-2022-41328","CVE-2023-22518","CVE-2023-22952","CVE-2023-32315","CVE-2023-34362","CVE-2023-3519","CVE-2023-43770","CVE-2024-23692","CVE-2024-27443","CVE-2024-42009","CVE-2024-4577","CVE-2025-32756"]},{"slug":"nsm-flow","name":"NSM:Flow","channels":[{"channel":"Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions","analytics":["AN1274"],"data_components":["DC0078"]},{"channel":"Abnormal browser traffic volume or destination","analytics":["AN0253"],"data_components":["DC0078"]},{"channel":"Altered response metadata or blocked content based on user-agent or geolocation","analytics":["AN1149"],"data_components":["DC0106"]},{"channel":"Base64 strings or gzip in URI, headers, or POST body","analytics":["AN0303"],"data_components":["DC0085"]},{"channel":"Browser connections to known C2 or dynamic DNS domains","analytics":["AN0125"],"data_components":["DC0085"]},{"channel":"C2 exfiltration","analytics":["AN0653"],"data_components":["DC0085"]},{"channel":"Captured File Content","analytics":["AN0652"],"data_components":["DC0085"]},{"channel":"Closed-port hits followed by success from same src_ip","analytics":["AN1450"],"data_components":["DC0082"]},{"channel":"Connection Tracking","analytics":["AN1230"],"data_components":["DC0078"]},{"channel":"Connections from IDE hosts to marketplace/tunnel domains","analytics":["AN1549"],"data_components":["DC0078"]},{"channel":"Connections to *.devtunnels.ms or tunnels.api.visualstudio.com","analytics":["AN0376"],"data_components":["DC0082"]},{"channel":"Connections to TCP 427 (SLP) or vCenter web services from untrusted sources","analytics":["AN0224"],"data_components":["DC0085"]},{"channel":"Content injection observed in HTTPS responses with mismatched certificates or altered payloads","analytics":["AN0994"],"data_components":["DC0085"]},{"channel":"DHCP OFFER or ACK with unauthorized DNS/gateway parameters","analytics":["AN1290"],"data_components":["DC0085"]},{"channel":"Degraded encryption throughput or switch to weaker cipher suites compared to historical baselines","analytics":["AN1360"],"data_components":["DC0085"]},{"channel":"Device-to-Device Deployment Flows","analytics":["AN0627"],"data_components":["DC0078"]},{"channel":"DrsAddEntry, DrsReplicaAdd, GetNCChanges calls between non-DC and DCs.","analytics":["AN0770"],"data_components":["DC0085"]},{"channel":"Egress to non-approved networks from host after terminal exec","analytics":["AN0964"],"data_components":["DC0085"]},{"channel":"Encrypted tunnels or proxy traffic to non-standard destinations","analytics":["AN1151"],"data_components":["DC0085"]},{"channel":"Excessive gratuitous ARP replies on local subnet","analytics":["AN1093"],"data_components":["DC0085"]},{"channel":"External access to container ports (2375, 6443)","analytics":["AN1007"],"data_components":["DC0082"]},{"channel":"First-time egress from host after new install to unknown update endpoints","analytics":["AN1480"],"data_components":["DC0078"]},{"channel":"First-time egress to new registries/CDNs post-install/build","analytics":["AN0022"],"data_components":["DC0078"]},{"channel":"First-time egress to non-approved registries after dependency install","analytics":["AN0023"],"data_components":["DC0078"]},{"channel":"First-time egress to non-approved update hosts right after install/update","analytics":["AN0862"],"data_components":["DC0078"]},{"channel":"First-time egress to unknown registries/mirrors immediately after install","analytics":["AN1481"],"data_components":["DC0078"]},{"channel":"First-time outbound connections to package registries or unknown hosts immediately after restore/build","analytics":["AN0021"],"data_components":["DC0078"]},{"channel":"Flow Creation (NetFlow/sFlow)","analytics":["AN1233"],"data_components":["DC0078"]},{"channel":"Flow records with RSA key exchange on unexpected port","analytics":["AN1500"],"data_components":["DC0078"]},{"channel":"Flow records with entropy signatures resembling symmetric encryption","analytics":["AN0404"],"data_components":["DC0078"]},{"channel":"Flow/PCAP analysis for outbound payloads","analytics":["AN0988"],"data_components":["DC0085"]},{"channel":"Gratuitous ARP replies with mismatched IP-MAC binding","analytics":["AN1092"],"data_components":["DC0078"]},{"channel":"Gratuitous or duplicate DHCP OFFER packets from non-legitimate servers","analytics":["AN1291"],"data_components":["DC0078"]},{"channel":"HTTP ","analytics":["AN0144"],"data_components":["DC0085"]},{"channel":"HTTP Request Logging","analytics":["AN1320"],"data_components":["DC0085"]},{"channel":"HTTP payloads with SQLi/LFI/JNDI/deserialization indicators","analytics":["AN0220"],"data_components":["DC0085"]},{"channel":"HTTP(S) requests with User-Agents typical of PowerShell or curl from desktop; or URIs matching paste-inspired payload hosts","analytics":["AN0962"],"data_components":["DC0085"]},{"channel":"HTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects)","analytics":["AN0500"],"data_components":["DC0085"]},{"channel":"HTTP/TLS Logs","analytics":["AN0159"],"data_components":["DC0085"]},{"channel":"HTTP/WebDAV requests that contain NTLMSSP or PROPFIND/MOVE/OPTIONS with Authorization: NTLM","analytics":["AN0065"],"data_components":["DC0085"]},{"channel":"HTTPS API requests to Dropbox, iCloud, Google Drive, OneDrive shortly after DB tool usage","analytics":["AN0678"],"data_components":["DC0085"]},{"channel":"HTTPs connection to tunnels.api.visualstudio.com","analytics":["AN0377"],"data_components":["DC0082"]},{"channel":"High volume flows with incomplete TCP sessions or single-packet bursts","analytics":["AN1435"],"data_components":["DC0078"]},{"channel":"High volumes of SYN/ACK packets with unacknowledged TCP handshakes","analytics":["AN1013"],"data_components":["DC0078"]},{"channel":"High-volume or repeated SNMP GETBULK/GETNEXT queries from untrusted or external IPs","analytics":["AN1249"],"data_components":["DC0082"]},{"channel":"ICMP/UDP monitoring (tcpdump, Wireshark, Zeek)","analytics":["AN1256"],"data_components":["DC0085"]},{"channel":"ICMP/UDP traffic (Wireshark, Suricata, Zeek)","analytics":["AN1254"],"data_components":["DC0085"]},{"channel":"Inbound HTTP POST with suspicious payload size or user-agent","analytics":["AN1108","AN2029","AN2032"],"data_components":["DC0085"]},{"channel":"Inbound connections to 445, 3389, 5985-5986 with high error/connection-reset rate, followed by new outbound sessions from the same host to internal assets within short interval.","analytics":["AN0327"],"data_components":["DC0085"]},{"channel":"Inbound connections to monitored service ports from external or unusual internal sources; rapid follow-on lateral connections from the same host.","analytics":["AN0328"],"data_components":["DC0085"]},{"channel":"Inbound one-off packet to uncommon port → outbound SF to same src_ip within TimeWindow.","analytics":["AN0464"],"data_components":["DC0085"]},{"channel":"Inbound to 22/5900/8080 and follow-on internal connections.","analytics":["AN0330"],"data_components":["DC0085"]},{"channel":"Inbound to tcp/427 (OpenSLP), tcp/443 (vSphere APIs), tcp/902, tcp/5989 followed by new unexpected outbound sessions from the ESXi/vCenter host.","analytics":["AN0329"],"data_components":["DC0085"]},{"channel":"Injected content responses with unexpected script/malware signatures","analytics":["AN0993"],"data_components":["DC0085"]},{"channel":"Inter-segment traffic","analytics":["AN0208"],"data_components":["DC0078"]},{"channel":"Knock pattern: multiple REJ/S0 to distinct closed ports then successful connection to service_port","analytics":["AN1449"],"data_components":["DC0078"]},{"channel":"Knock pattern: repeated REJ/S0 across ≥MinSequenceLen ports from same src_ip then SF success.","analytics":["AN0843"],"data_components":["DC0078"]},{"channel":"LDAP Bind/Search","analytics":["AN0363"],"data_components":["DC0085"]},{"channel":"LDAP Query","analytics":["AN0364"],"data_components":["DC0085"]},{"channel":"LEASE_GRANTED","analytics":["AN0186"],"data_components":["DC0078"]},{"channel":"Long-lived or hijacked SSH sessions maintained with no active user activity","analytics":["AN0217"],"data_components":["DC0078"]},{"channel":"MAC not in allow-list acquiring IP (DHCP)","analytics":["AN0187"],"data_components":["DC0078"]},{"channel":"Multiple DHCP OFFER responses for a single DISCOVER","analytics":["AN1292"],"data_components":["DC0085"]},{"channel":"NetFlow/Zeek conn.log","analytics":["AN0368"],"data_components":["DC0078"]},{"channel":"NetFlow/sFlow for odd egress to Internet from mgmt plane","analytics":["AN0225"],"data_components":["DC0085"]},{"channel":"NetFlow/sFlow/PCAP","analytics":["AN0596"],"data_components":["DC0078"]},{"channel":"Network Capture TLS/HTTP","analytics":["AN1295"],"data_components":["DC0085"]},{"channel":"New VM egress to crypto-mining pools or non-approved Internet ranges within minutes of boot","analytics":["AN0692"],"data_components":["DC0085"]},{"channel":"New egress from app just installed to unknown update endpoints","analytics":["AN1482"],"data_components":["DC0078"]},{"channel":"New egress from container IP/namespace to Internet or non-approved CIDRs/ASNs","analytics":["AN0691"],"data_components":["DC0085"]},{"channel":"New egress to Internet by the same UID/host shortly after terminal exec","analytics":["AN0963"],"data_components":["DC0082"]},{"channel":"New outbound flows to non-approved vendor hosts post install","analytics":["AN0863"],"data_components":["DC0078"]},{"channel":"New/rare egress to non-approved update hosts after install","analytics":["AN0864"],"data_components":["DC0078"]},{"channel":"None","analytics":["AN0213","AN1378"],"data_components":["DC0078"]},{"channel":"Observed File Transfers","analytics":["AN0652"],"data_components":["DC0059"]},{"channel":"Observed downgrade in negotiated cipher suites or TLS/SSH versions across sessions","analytics":["AN0681"],"data_components":["DC0085"]},{"channel":"Outbound Connections","analytics":["AN1114","AN1119"],"data_components":["DC0082"]},{"channel":"Outbound HTTP/S","analytics":["AN1408"],"data_components":["DC0085"]},{"channel":"Outbound HTTP/S initiated by newly installed interpreter process","analytics":["AN0700"],"data_components":["DC0082"]},{"channel":"Outbound Network Flow","analytics":["AN0597"],"data_components":["DC0078"]},{"channel":"Outbound SCP, TFTP, or FTP sessions carrying configuration file content","analytics":["AN0647"],"data_components":["DC0085"]},{"channel":"Outbound TCP SYN or UDP to multiple ports/hosts","analytics":["AN1058"],"data_components":["DC0078"]},{"channel":"Outbound UDP floods targeting common reflection services with spoofed IP headers","analytics":["AN1141"],"data_components":["DC0078"]},{"channel":"Outbound connection to *.tunnels.api.visualstudio.com or *.devtunnels.ms","analytics":["AN0375"],"data_components":["DC0082"]},{"channel":"Outbound connection to mining pool port (3333, 4444, 5555)","analytics":["AN1490"],"data_components":["DC0078"]},{"channel":"Outbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs","analytics":["AN1508"],"data_components":["DC0078"]},{"channel":"Outbound connections to TCP 139,445 and HTTP/HTTPS to WebDAV endpoints from workstation subnets","analytics":["AN0065"],"data_components":["DC0078"]},{"channel":"Outbound flow records","analytics":["AN0926"],"data_components":["DC0078"]},{"channel":"Outbound or inbound TFTP file transfers of ROMMON or firmware binaries","analytics":["AN0497"],"data_components":["DC0082"]},{"channel":"Outbound requests to domains not previously resolved or associated with phishing campaigns","analytics":["AN0299"],"data_components":["DC0078"]},{"channel":"Outbound traffic from suspicious new processes post-attachment execution","analytics":["AN0656"],"data_components":["DC0078"]},{"channel":"Outbound traffic spike through formerly blocked ports/subnets following config change","analytics":["AN0855"],"data_components":["DC0082"]},{"channel":"Outbound traffic to domains/IPs not previously resolved, occurring shortly after attachment download or link click","analytics":["AN0321"],"data_components":["DC0078"]},{"channel":"Outbound traffic to mining pool upon container launch","analytics":["AN1492"],"data_components":["DC0078"]},{"channel":"Outbound traffic to mining pools or proxies","analytics":["AN0742"],"data_components":["DC0078"]},{"channel":"PCAP inspection","analytics":["AN0427"],"data_components":["DC0085"]},{"channel":"POST requests to .php, .jsp, .aspx files with high entropy body","analytics":["AN1109"],"data_components":["DC0085"]},{"channel":"Packets with unusual flags or payloads outside established flows (e.g., WoL magic FF×6 + 16×MAC)","analytics":["AN1449"],"data_components":["DC0085"]},{"channel":"Port-knock pattern from one src to device unicast,broadcast,network addresses on same port within TimeWindowKnock","analytics":["AN1451"],"data_components":["DC0082"]},{"channel":"Probe responses from unauthorized APs responding to client probe requests","analytics":["AN1069"],"data_components":["DC0085"]},{"channel":"Rare inbound packet characteristics (ICMP/UDP/TCP to uncommon port) from src_ip followed ≤TimeWindow by outbound SF from same host to src_ip.","analytics":["AN0463"],"data_components":["DC0085"]},{"channel":"Relay patterns across IP hops","analytics":["AN1023"],"data_components":["DC0085"]},{"channel":"Relayed session pathing (multi-hop)","analytics":["AN1024"],"data_components":["DC0078"]},{"channel":"Requests towards cloud metadata or command & control from pod IPs","analytics":["AN0222"],"data_components":["DC0085"]},{"channel":"SMB2_LOGOFF/SMB_TREE_DISCONNECT","analytics":["AN0286"],"data_components":["DC0085"]},{"channel":"SPAN or port-mirrored HTTP/S","analytics":["AN0078"],"data_components":["DC0085"]},{"channel":"SSH logins or scp activity","analytics":["AN0195"],"data_components":["DC0085"]},{"channel":"SSL/TLS Handshake Analysis","analytics":["AN1294"],"data_components":["DC0085"]},{"channel":"SSL/TLS Inspection or PCAP","analytics":["AN1189"],"data_components":["DC0085"]},{"channel":"Sequence of REJ/S0 then SF success from same src_ip within TimeWindow.","analytics":["AN0844"],"data_components":["DC0082"]},{"channel":"Series of denied/closed flows to distinct ports then success to mgmt port from same src_ip within TimeWindow.","analytics":["AN0845"],"data_components":["DC0082"]},{"channel":"Session History Reset","analytics":["AN0136"],"data_components":["DC0085"]},{"channel":"Session Transfer Content","analytics":["AN0651"],"data_components":["DC0085"]},{"channel":"Session records with TLS-like byte patterns","analytics":["AN0763"],"data_components":["DC0078"]},{"channel":"Single, low-volume inbound packet (REJ/S0/OTH or uncommon dport/protocol) from src_ip followed by outbound SF connection to src_ip.","analytics":["AN0462"],"data_components":["DC0085"]},{"channel":"Source/destination IP translation inconsistent with intended policy","analytics":["AN0465"],"data_components":["DC0078"]},{"channel":"Sudden spike in incoming flows to web service ports from single/multiple IPs","analytics":["AN0490"],"data_components":["DC0078"]},{"channel":"Suspicious POSTs to upload endpoints","analytics":["AN1623"],"data_components":["DC0085"]},{"channel":"Suspicious URL patterns, uncommon TLDs, URL shorteners","analytics":["AN0179"],"data_components":["DC0085"]},{"channel":"Suspicious URL patterns, uncommon TLDs, short-lived domains, URL shorteners; HTTP method GET/POST","analytics":["AN0178"],"data_components":["DC0085"]},{"channel":"Suspicious changes in TLS certificate responses or redirected domains","analytics":["AN1150"],"data_components":["DC0104"]},{"channel":"Suspicious long-lived or reattached remote desktop sessions from unexpected IPs","analytics":["AN0218"],"data_components":["DC0085"]},{"channel":"Sustained abnormal inbound request rate targeting application ports (e.g., 80/443/25)","analytics":["AN1166"],"data_components":["DC0085"]},{"channel":"TCP port 22 traffic","analytics":["AN1638"],"data_components":["DC0078"]},{"channel":"TCP port 5900 open","analytics":["AN0505"],"data_components":["DC0078"]},{"channel":"TCP session tracking","analytics":["AN0031"],"data_components":["DC0085"]},{"channel":"TCP/UDP","analytics":["AN0030"],"data_components":["DC0085"]},{"channel":"TCP: possible SYN flood or backlog limit exceeded","analytics":["AN1013"],"data_components":["DC0018"]},{"channel":"TGS-REQ and AS-REQ seen for new user shortly after domain-modifying process","analytics":["AN0007"],"data_components":["DC0002"]},{"channel":"TLS downgrade or inconsistent DNS answers","analytics":["AN0825"],"data_components":["DC0085"]},{"channel":"Traffic patterns showing downgrade from strong encryption (AES-256) to weaker or plaintext protocols","analytics":["AN0961"],"data_components":["DC0085"]},{"channel":"Traffic spike preceding control crash","analytics":["AN2040"],"data_components":["DC0085"]},{"channel":"Transferred file observations","analytics":["AN0654"],"data_components":["DC0085"]},{"channel":"Unexpected ARP replies or DNS responses inconsistent with authoritative servers","analytics":["AN0824"],"data_components":["DC0085"]},{"channel":"Unexpected flows between segmented networks or prohibited ports","analytics":["AN0015"],"data_components":["DC0078"]},{"channel":"Unexpected inbound/outbound TFTP traffic for device image files","analytics":["AN1603"],"data_components":["DC0082"]},{"channel":"Unexpected or unauthorized inbound connections to SNMP, NETCONF, or RESTCONF services","analytics":["AN1630"],"data_components":["DC0082"]},{"channel":"Unexpected route changes or duplicate gateway advertisements","analytics":["AN0826"],"data_components":["DC0078"]},{"channel":"Unexpected script or binary content returned in HTTP response body","analytics":["AN0992"],"data_components":["DC0085"]},{"channel":"Unusual Base64-encoded content in URI, headers, or POST body","analytics":["AN0302"],"data_components":["DC0085"]},{"channel":"Unusual request pattern leading up to service crash (e.g., malformed or oversized payload)","analytics":["AN0851"],"data_components":["DC0085"]},{"channel":"Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts","analytics":["AN1274"],"data_components":["DC0085"]},{"channel":"alert log","analytics":["AN0923"],"data_components":["DC0078"]},{"channel":"alternate ports","analytics":["AN1377"],"data_components":["DC0078"]},{"channel":"conn.log","analytics":["AN0101","AN0205","AN0207","AN0925","AN1232","AN1382"],"data_components":["DC0078","DC0082","DC0085"]},{"channel":"conn.log + files.log + ssl.log","analytics":["AN0989"],"data_components":["DC0085"]},{"channel":"conn.log + ssl.log with Tor fingerprinting","analytics":["AN1021"],"data_components":["DC0078"]},{"channel":"conn.log or flow data","analytics":["AN1390"],"data_components":["DC0078"]},{"channel":"conn.log or http.log","analytics":["AN0923"],"data_components":["DC0085"]},{"channel":"conn.log, http.log, dns.log, ssl.log","analytics":["AN1228"],"data_components":["DC0085"]},{"channel":"conn.log, icmp.log","analytics":["AN1258"],"data_components":["DC0078"]},{"channel":"conn.log, ssl.log","analytics":["AN1190"],"data_components":["DC0085"]},{"channel":"connection attempts","analytics":["AN1231"],"data_components":["DC0082"]},{"channel":"connection metadata","analytics":["AN0169"],"data_components":["DC0078"]},{"channel":"connection: Inbound connections to SSH or VPN ports","analytics":["AN1005"],"data_components":["DC0082"]},{"channel":"connection: SMB connections to multiple internal hosts","analytics":["AN0515"],"data_components":["DC0082"]},{"channel":"connection: TCP connections to ports 139/445 to multiple hosts","analytics":["AN0514"],"data_components":["DC0082"]},{"channel":"container egress to unknown IPs/domains","analytics":["AN1317"],"data_components":["DC0085"]},{"channel":"dns, ssl, conn","analytics":["AN1226"],"data_components":["DC0085"]},{"channel":"dns.log","analytics":["AN1121","AN1122","AN1124","AN1125"],"data_components":["DC0085"]},{"channel":"flow records","analytics":["AN0424","AN0426"],"data_components":["DC0078"]},{"channel":"ftp.log, conn.log","analytics":["AN1170"],"data_components":["DC0085"]},{"channel":"ftp.log, conn.log, smb_files.log","analytics":["AN1173"],"data_components":["DC0085"]},{"channel":"ftp.log, smb_files.log","analytics":["AN1169"],"data_components":["DC0085"]},{"channel":"host switch egress data","analytics":["AN1392"],"data_components":["DC0085"]},{"channel":"http, dns, smb, ssl logs","analytics":["AN1225"],"data_components":["DC0085"]},{"channel":"http.log","analytics":["AN0285","AN0426"],"data_components":["DC0085"]},{"channel":"http.log, conn.log","analytics":["AN0076","AN2031"],"data_components":["DC0085"]},{"channel":"http.log, files.log","analytics":["AN0058"],"data_components":["DC0085"]},{"channel":"http.log, ftp.log","analytics":["AN0423","AN0424","AN0425"],"data_components":["DC0085"]},{"channel":"http.log, ssl.log","analytics":["AN0075"],"data_components":["DC0085"]},{"channel":"http.log, ssl.log, websocket.log","analytics":["AN0079"],"data_components":["DC0085"]},{"channel":"http.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources","analytics":["AN0498"],"data_components":["DC0085"]},{"channel":"http/file-xfer: Inbound/outbound transfer of ELF shared objects","analytics":["AN0053"],"data_components":["DC0085"]},{"channel":"http/file-xfer: Outbound transfer of large video-like MIME types soon after capture","analytics":["AN0569"],"data_components":["DC0085"]},{"channel":"http: Base64/MIME looking payloads from ESXi host IP","analytics":["AN0348"],"data_components":["DC0085"]},{"channel":"http: HTTP bodies from ESXi host IPs containing long, non-standard tokens","analytics":["AN0930"],"data_components":["DC0085"]},{"channel":"http: HTTP bodies/headers contain long tokens with non-standard alphabets or constant-size periodic POSTs","analytics":["AN0928"],"data_components":["DC0085"]},{"channel":"http: HTTP body contains long Base64 sections","analytics":["AN0347"],"data_components":["DC0085"]},{"channel":"http: HTTP body or headers contain long Base64 sections; gzip/deflate + Base64","analytics":["AN0346"],"data_components":["DC0085"]},{"channel":"http: suspicious long tokens with custom alphabets in body/headers","analytics":["AN0929"],"data_components":["DC0085"]},{"channel":"http::post: Outbound HTTP POST from host shortly after DB export activity","analytics":["AN0676"],"data_components":["DC0085"]},{"channel":"http::request: Network connection to package registry or C2 from interpreter shortly after install","analytics":["AN0698"],"data_components":["DC0085"]},{"channel":"http::request: Outbound HTTP initiated by Python interpreter","analytics":["AN0713"],"data_components":["DC0085"]},{"channel":"http::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domains","analytics":["AN0499"],"data_components":["DC0085"]},{"channel":"icmp.log, weird.log","analytics":["AN1255"],"data_components":["DC0085"]},{"channel":"large HTTPS POST requests to text storage domains","analytics":["AN0788"],"data_components":["DC0085"]},{"channel":"large HTTPS POST requests to webhook endpoints","analytics":["AN0437"],"data_components":["DC0085"]},{"channel":"large HTTPS outbound uploads","analytics":["AN1572"],"data_components":["DC0078"]},{"channel":"large outbound HTTPS uploads to repo domains","analytics":["AN0896"],"data_components":["DC0078"]},{"channel":"large outbound data flows or long-duration connections","analytics":["AN0081"],"data_components":["DC0078"]},{"channel":"large transfer from management IPs to unauthorized host","analytics":["AN1159"],"data_components":["DC0085"]},{"channel":"large upload to firmware interface port or path","analytics":["AN0477"],"data_components":["DC0085"]},{"channel":"ldap.log","analytics":["AN1026"],"data_components":["DC0085"]},{"channel":"log entries indicating network connection initiation on macOS","analytics":["AN2065"],"data_components":["DC0082"]},{"channel":"mirror/SPAN port","analytics":["AN1172"],"data_components":["DC0085"]},{"channel":"mqtt.log / xmpp.log (custom log feeds)","analytics":["AN0002"],"data_components":["DC0085"]},{"channel":"mqtt.log or AMQP custom log","analytics":["AN0003"],"data_components":["DC0085"]},{"channel":"mqtt.log, xmpp.log, amqp.log","analytics":["AN0005"],"data_components":["DC0085"]},{"channel":"network_flow: bytes_out >> bytes_in, fixed packet sizes/intervals to non-approved CIDRs","analytics":["AN0930"],"data_components":["DC0078"]},{"channel":"new outbound connection from browser/office lineage","analytics":["AN1315"],"data_components":["DC0082"]},{"channel":"new outbound connection from exploited lineage","analytics":["AN1316"],"data_components":["DC0082"]},{"channel":"outbound connections from host during or immediately after image build","analytics":["AN1261"],"data_components":["DC0082"]},{"channel":"outbound connections to RMM services or to unusual destination ports","analytics":["AN0715"],"data_components":["DC0082"]},{"channel":"outbound egress from web host after suspicious request","analytics":["AN0221"],"data_components":["DC0085"]},{"channel":"packet capture or DPI logs","analytics":["AN0246"],"data_components":["DC0085"]},{"channel":"pf firewall logs","analytics":["AN0206","AN0924"],"data_components":["DC0078"]},{"channel":"port 5900 inbound","analytics":["AN0504"],"data_components":["DC0078"]},{"channel":"query: High-volume LDAP traffic with filters targeting groupPolicyContainer attributes","analytics":["AN0152"],"data_components":["DC0085"]},{"channel":"remote CLI session detection","analytics":["AN0399"],"data_components":["DC0085"]},{"channel":"remote access","analytics":["AN1084"],"data_components":["DC0082"]},{"channel":"remote login and transfer","analytics":["AN0196"],"data_components":["DC0085"]},{"channel":"session behavior","analytics":["AN0032"],"data_components":["DC0085"]},{"channel":"session stats with bytes_out > bytes_in","analytics":["AN0989"],"data_components":["DC0078"]},{"channel":"smb_command: TreeConnectAndX to \\\\*\\IPC$ / srvsvc or Trans2/NT_CREATE for listing shares","analytics":["AN0514"],"data_components":["DC0021"]},{"channel":"smb_files.log","analytics":["AN1299"],"data_components":["DC0102"]},{"channel":"smtp.log","analytics":["AN0379"],"data_components":["DC0085"]},{"channel":"smtp.log, conn.log","analytics":["AN0380","AN0382"],"data_components":["DC0085"]},{"channel":"ssh connections originating from third-party CIDRs","analytics":["AN1345"],"data_components":["DC0085"]},{"channel":"ssh/smb connections to internal resources from third-party devices","analytics":["AN1346"],"data_components":["DC0085"]},{"channel":"ssl.log","analytics":["AN0101"],"data_components":["DC0085"]},{"channel":"ssl.log (for TLS handshake analysis), dns.log (tunneling indicators)","analytics":["AN1390"],"data_components":["DC0085"]},{"channel":"ssl.log + http.log","analytics":["AN0565"],"data_components":["DC0085"]},{"channel":"ssl.log - Certificate Analysis","analytics":["AN1413"],"data_components":["DC0085"]},{"channel":"ssl.log, conn.log","analytics":["AN1414"],"data_components":["DC0085"]},{"channel":"ssl.log, x509.log","analytics":["AN1415"],"data_components":["DC0085"]},{"channel":"sustained outbound HTTPS sessions with high data volume","analytics":["AN1512"],"data_components":["DC0078"]},{"channel":"uncommon ports","analytics":["AN1376"],"data_components":["DC0078"]},{"channel":"unexpected network activity initiated shortly after shell session starts","analytics":["AN0059"],"data_components":["DC0085"]}],"data_components":["DC0002","DC0018","DC0021","DC0059","DC0078","DC0082","DC0085","DC0102","DC0104","DC0106"],"analytics":["AN0002","AN0003","AN0005","AN0007","AN0015","AN0021","AN0022","AN0023","AN0030","AN0031","AN0032","AN0053","AN0058","AN0059","AN0065","AN0075","AN0076","AN0078","AN0079","AN0081","AN0101","AN0125","AN0136","AN0144","AN0152","AN0159","AN0169","AN0178","AN0179","AN0186","AN0187","AN0195","AN0196","AN0205","AN0206","AN0207","AN0208","AN0213","AN0217","AN0218","AN0220","AN0221","AN0222","AN0224","AN0225","AN0246","AN0253","AN0285","AN0286","AN0299","AN0302","AN0303","AN0321","AN0327","AN0328","AN0329","AN0330","AN0346","AN0347","AN0348","AN0363","AN0364","AN0368","AN0375","AN0376","AN0377","AN0379","AN0380","AN0382","AN0399","AN0404","AN0423","AN0424","AN0425","AN0426","AN0427","AN0437","AN0462","AN0463","AN0464","AN0465","AN0477","AN0490","AN0497","AN0498","AN0499","AN0500","AN0504","AN0505","AN0514","AN0515","AN0565","AN0569","AN0596","AN0597","AN0627","AN0647","AN0651","AN0652","AN0653","AN0654","AN0656","AN0676","AN0678","AN0681","AN0691","AN0692","AN0698","AN0700","AN0713","AN0715","AN0742","AN0763","AN0770","AN0788","AN0824","AN0825","AN0826","AN0843","AN0844","AN0845","AN0851","AN0855","AN0862","AN0863","AN0864","AN0896","AN0923","AN0924","AN0925","AN0926","AN0928","AN0929","AN0930","AN0961","AN0962","AN0963","AN0964","AN0988","AN0989","AN0992","AN0993","AN0994","AN1005","AN1007","AN1013","AN1021","AN1023","AN1024","AN1026","AN1058","AN1069","AN1084","AN1092","AN1093","AN1108","AN1109","AN1114","AN1119","AN1121","AN1122","AN1124","AN1125","AN1141","AN1149","AN1150","AN1151","AN1159","AN1166","AN1169","AN1170","AN1172","AN1173","AN1189","AN1190","AN1225","AN1226","AN1228","AN1230","AN1231","AN1232","AN1233","AN1249","AN1254","AN1255","AN1256","AN1258","AN1261","AN1274","AN1290","AN1291","AN1292","AN1294","AN1295","AN1299","AN1315","AN1316","AN1317","AN1320","AN1345","AN1346","AN1360","AN1376","AN1377","AN1378","AN1382","AN1390","AN1392","AN1408","AN1413","AN1414","AN1415","AN1435","AN1449","AN1450","AN1451","AN1480","AN1481","AN1482","AN1490","AN1492","AN1500","AN1508","AN1512","AN1549","AN1572","AN1603","AN1623","AN1630","AN1638","AN2029","AN2031","AN2032","AN2040","AN2065"],"techniques":["T1001","T1001.001","T1001.002","T1001.003","T1008","T1011","T1020","T1021.004","T1021.005","T1027.004","T1027.008","T1027.017","T1027.018","T1029","T1030","T1036.012","T1041","T1046","T1048","T1048.001","T1048.002","T1048.003","T1056","T1056.001","T1056.003","T1059.004","T1059.008","T1069.002","T1070.005","T1070.007","T1071","T1071.001","T1071.002","T1071.003","T1071.004","T1071.005","T1072","T1074.002","T1080","T1087.002","T1090","T1090.001","T1090.002","T1090.003","T1090.004","T1095","T1102","T1102.001","T1102.002","T1105","T1125","T1129","T1132","T1132.001","T1132.002","T1133","T1135","T1136.002","T1176","T1176.001","T1176.002","T1187","T1189","T1190","T1195","T1195.001","T1195.002","T1199","T1200","T1204","T1204.001","T1204.003","T1204.004","T1204.005","T1205","T1205.001","T1205.002","T1207","T1210","T1213.006","T1219.001","T1219.002","T1491.002","T1495","T1496","T1496.001","T1496.002","T1498","T1498.002","T1499.001","T1499.002","T1499.003","T1499.004","T1505","T1505.003","T1542.004","T1542.005","T1546.004","T1546.018","T1552","T1557","T1557.001","T1557.002","T1557.003","T1557.004","T1563","T1566.001","T1566.002","T1566.003","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1573","T1573.001","T1573.002","T1599","T1599.001","T1600","T1600.001","T1600.002","T1602","T1602.001","T1602.002","T1612","T1615","T1659","T1665","T1686.002","T1687"],"platforms":["Containers","ESXi","Linux","Network Devices","Windows","macOS"],"kev_cves":["CVE-2009-3960","CVE-2009-4324","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2011-0611","CVE-2012-0754","CVE-2012-0767","CVE-2012-1535","CVE-2012-2034","CVE-2012-5054","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0640","CVE-2013-0641","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-3113","CVE-2015-5119","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1019","CVE-2016-4117","CVE-2016-4437","CVE-2016-7855","CVE-2017-11292","CVE-2017-11882","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-15982","CVE-2018-4878","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-0708","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-0688","CVE-2020-1472","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-3580","CVE-2020-5902","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26855","CVE-2021-26857","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40449","CVE-2021-40539","CVE-2021-40655","CVE-2021-41773","CVE-2021-42013","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20699","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-21971","CVE-2022-22947","CVE-2022-22954","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-24682","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-30190","CVE-2022-3038","CVE-2022-3075","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-41033","CVE-2022-41082","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-1389","CVE-2023-20118","CVE-2023-20198","CVE-2023-20269","CVE-2023-20867","CVE-2023-20887","CVE-2023-2136","CVE-2023-22515","CVE-2023-22518","CVE-2023-22527","CVE-2023-22952","CVE-2023-2533","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27532","CVE-2023-27997","CVE-2023-2868","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-32315","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-39780","CVE-2023-40044","CVE-2023-42793","CVE-2023-43770","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-7024","CVE-2023-7101","CVE-2024-0769","CVE-2024-11120","CVE-2024-11182","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20439","CVE-2024-20953","CVE-2024-21413","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-24919","CVE-2024-27198","CVE-2024-27443","CVE-2024-34102","CVE-2024-38112","CVE-2024-38475","CVE-2024-40890","CVE-2024-40891","CVE-2024-42009","CVE-2024-4358","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-48248","CVE-2024-4879","CVE-2024-49035","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-5274","CVE-2024-53150","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-0411","CVE-2025-1316","CVE-2025-21480","CVE-2025-22457","CVE-2025-23006","CVE-2025-24201","CVE-2025-24993","CVE-2025-25257","CVE-2025-27363","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-32756","CVE-2025-33053","CVE-2025-34028","CVE-2025-35939","CVE-2025-3928","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5419","CVE-2025-54309","CVE-2025-5777","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"cloudtrail-getobject","name":"CloudTrail:GetObject","channels":[{"channel":"sensitive credential files in buckets or local image storage","analytics":["AN0860"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN0860"],"techniques":["T1552.001"],"platforms":["IaaS"],"kev_cves":["CVE-2019-11510","CVE-2022-26138","CVE-2024-57727"]},{"slug":"networkconfig","name":"networkconfig ","channels":[{"channel":"interface flag PROMISC, netstat | ip link | ethtool","analytics":["AN0876"],"data_components":["DC0085"]},{"channel":"unexpected OS image file upload or modification events","analytics":["AN0758"],"data_components":["DC0061"]}],"data_components":["DC0061","DC0085"],"analytics":["AN0758","AN0876"],"techniques":["T1040","T1556.004"],"platforms":["Linux","Network Devices"],"kev_cves":["CVE-2021-32030","CVE-2022-1040"]},{"slug":"application-mail","name":"Application:Mail","channels":[{"channel":"High-frequency inbound mail activity to a specific recipient address","analytics":["AN1009"],"data_components":["DC0038"]},{"channel":"Inbound email attachments logged from MTAs with suspicious metadata","analytics":["AN0656"],"data_components":["DC0038"]},{"channel":"Inbound emails containing hyperlinks from suspicious sources","analytics":["AN0299"],"data_components":["DC0038"]},{"channel":"Inbound messages with anomalous headers, spoofed SPF/DKIM failures","analytics":["AN0189"],"data_components":["DC0038"]},{"channel":"Mismatch between authenticated username and From header in email","analytics":["AN0793"],"data_components":["DC0038"]},{"channel":"smtpd$.*$: .*from=[.*@internaldomain.com](mailto:.*@internaldomain.com) to=[.*@internaldomain.com](mailto:.*@internaldomain.com)","analytics":["AN0148"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0148","AN0189","AN0299","AN0656","AN0793","AN1009"],"techniques":["T1534","T1566","T1566.001","T1566.002","T1667","T1684.001"],"platforms":["Linux"],"kev_cves":["CVE-2013-0640","CVE-2015-5119","CVE-2017-11292","CVE-2017-11882","CVE-2021-40449","CVE-2022-34713","CVE-2022-41033","CVE-2022-41128","CVE-2023-2533","CVE-2023-2868","CVE-2023-36884","CVE-2024-11182","CVE-2024-21413","CVE-2024-27443","CVE-2024-42009","CVE-2025-0411","CVE-2025-24054","CVE-2025-33053"]},{"slug":"macos-osquery","name":"macos:osquery","channels":[{"channel":"CALCULATE: Integrity validation of transmitted data via hash checks","analytics":["AN0704"],"data_components":["DC0021"]},{"channel":"CALCULATE: Mismatch in file integrity of critical macOS applications","analytics":["AN1099"],"data_components":["DC0061"]},{"channel":"CONNECT: Long-lived connections from remote-control parents to external IPs/domains","analytics":["AN1368"],"data_components":["DC0082"]},{"channel":"CREATE, DELETE, WRITE: Stored data manipulation attempts by unauthorized processes","analytics":["AN0557"],"data_components":["DC0040"]},{"channel":"CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations","analytics":["AN1368"],"data_components":["DC0039"]},{"channel":"CREATE/MODIFY: Modification of app.asar inside .app bundle","analytics":["AN0073"],"data_components":["DC0039"]},{"channel":"Changes to LSFileQuarantineEnabled field in Info.plist","analytics":["AN0800"],"data_components":["DC0061"]},{"channel":"Execution of flooding tools or compiled packet generators","analytics":["AN1014"],"data_components":["DC0032"]},{"channel":"Execution of non-standard binaries accessing Kerberos APIs","analytics":["AN0070"],"data_components":["DC0032"]},{"channel":"File modifications in ~/Library/Preferences/","analytics":["AN0522"],"data_components":["DC0061"]},{"channel":"Interpreter exec with suspicious arguments as above","analytics":["AN0964"],"data_components":["DC0064"]},{"channel":"Invocation of osascript or dylib injection","analytics":["AN0650"],"data_components":["DC0032"]},{"channel":"Memory Mappings","analytics":["AN0391"],"data_components":["DC0020"]},{"channel":"Modifications to /var/db/SystemPolicyConfiguration/KextPolicy or kext_policy table","analytics":["AN1244"],"data_components":["DC0061"]},{"channel":"New kext entries not signed by Apple or outside standard identifier prefix","analytics":["AN1244"],"data_components":["DC0031"]},{"channel":"None","analytics":["AN1533"],"data_components":["DC0055","DC0082"]},{"channel":"Process Context","analytics":["AN0097"],"data_components":["DC0034"]},{"channel":"Process Events and Launch Daemons","analytics":["AN0206"],"data_components":["DC0060"]},{"channel":"Process Execution + Hash","analytics":["AN1296"],"data_components":["DC0034"]},{"channel":"Processes executing kextload, spctl, or modifying kernel extension directories","analytics":["AN1244"],"data_components":["DC0032"]},{"channel":"Rapid spawning of resource-heavy applications (e.g., Preview, Safari, Office)","analytics":["AN1167"],"data_components":["DC0032"]},{"channel":"Unsigned or ad-hoc signed process executions in user contexts","analytics":["AN1248"],"data_components":["DC0032"]},{"channel":"code_signing, file_metadata","analytics":["AN0057"],"data_components":["DC0059"]},{"channel":"curl, python scripts, rsync with internal share URLs","analytics":["AN1163"],"data_components":["DC0032"]},{"channel":"detection of new launch agents with suspicious paths or unsigned binaries","analytics":["AN1208"],"data_components":["DC0060"]},{"channel":"exec","analytics":["AN0799","AN1316"],"data_components":["DC0032"]},{"channel":"exec: Unexpected execution of osascript or AppleScript targeting sensitive apps","analytics":["AN1359"],"data_components":["DC0029"]},{"channel":"execution of trusted tools interacting with external endpoints","analytics":["AN0228"],"data_components":["DC0082"]},{"channel":"execve","analytics":["AN0121","AN1563"],"data_components":["DC0032"]},{"channel":"execve: Processes unexpectedly invoking Keychain or authentication APIs","analytics":["AN0495"],"data_components":["DC0032"]},{"channel":"execve: Unsigned or unnotarized processes launched with high privileges","analytics":["AN1635"],"data_components":["DC0032"]},{"channel":"file_events","analytics":["AN0115","AN0135","AN0333","AN0344","AN0369","AN0542","AN0739","AN1066","AN1218","AN1383","AN1585","AN1628"],"data_components":["DC0039","DC0040","DC0055","DC0059","DC0061"]},{"channel":"interface_details ","analytics":["AN0214"],"data_components":["DC0018"]},{"channel":"launch_daemons","analytics":["AN1063"],"data_components":["DC0060"]},{"channel":"launchd","analytics":["AN0313"],"data_components":["DC0041"]},{"channel":"launchd + process_events","analytics":["AN1082"],"data_components":["DC0064"]},{"channel":"launchd or network_events","analytics":["AN0924"],"data_components":["DC0082"]},{"channel":"launchd or process_events","analytics":["AN0284"],"data_components":["DC0032"]},{"channel":"launchd, processes","analytics":["AN1482"],"data_components":["DC0032"]},{"channel":"launchd_jobs","analytics":["AN0260"],"data_components":["DC0001"]},{"channel":"mach_o_info, file_metadata","analytics":["AN0601"],"data_components":["DC0059"]},{"channel":"open, execve: Unexpected processes accessing or modifying critical files","analytics":["AN0164"],"data_components":["DC0021"]},{"channel":"parent_name in ('sshd','httpd','screensharingd') spawning shells or scripting runtimes.","analytics":["AN0330"],"data_components":["DC0032"]},{"channel":"process reading browser configuration paths","analytics":["AN0039"],"data_components":["DC0032"]},{"channel":"process_events","analytics":["AN0032","AN0173","AN0210","AN0214","AN0273","AN0333","AN0369","AN0425","AN0506","AN0566","AN0618","AN0653","AN0734","AN0752","AN0874","AN0905","AN0945","AN0990","AN1059","AN1327","AN1412","AN1415","AN1442","AN1639"],"data_components":["DC0032"]},{"channel":"process_events + launchd","analytics":["AN1022"],"data_components":["DC0082"]},{"channel":"process_events OR launchd","analytics":["AN0245"],"data_components":["DC0032"]},{"channel":"process_events where path like '%tcpdump%'","analytics":["AN0877"],"data_components":["DC0032"]},{"channel":"process_events, socket_events","analytics":["AN1191"],"data_components":["DC0082"]},{"channel":"process_events/socket_events","analytics":["AN0160"],"data_components":["DC0082"]},{"channel":"process_open","analytics":["AN0289"],"data_components":["DC0035"]},{"channel":"process_termination: Unexpected termination of processes tied to vulnerable or high-value services","analytics":["AN0047"],"data_components":["DC0033"]},{"channel":"query: Enumeration of root certificates showing unexpected additions","analytics":["AN0155"],"data_components":["DC0061"]},{"channel":"query: Historical list of associated SSIDs compared against baseline","analytics":["AN1478"],"data_components":["DC0078"]},{"channel":"query: process_events, launchd, and tcc.db access","analytics":["AN0689"],"data_components":["DC0032"]},{"channel":"socket_events","analytics":["AN0004","AN0077","AN0381","AN0425","AN0990","AN1171","AN1227","AN1391","AN1415"],"data_components":["DC0078"]},{"channel":"unexpected memory inspection","analytics":["AN1643"],"data_components":["DC0035"]},{"channel":"usb_devices","analytics":["AN1355"],"data_components":["DC0054"]},{"channel":"write","analytics":["AN1251"],"data_components":["DC0061"]}],"data_components":["DC0001","DC0018","DC0020","DC0021","DC0029","DC0031","DC0032","DC0033","DC0034","DC0035","DC0039","DC0040","DC0041","DC0054","DC0055","DC0059","DC0060","DC0061","DC0064","DC0078","DC0082"],"analytics":["AN0004","AN0032","AN0039","AN0047","AN0057","AN0070","AN0073","AN0077","AN0097","AN0115","AN0121","AN0135","AN0155","AN0160","AN0164","AN0173","AN0206","AN0210","AN0214","AN0228","AN0245","AN0260","AN0273","AN0284","AN0289","AN0313","AN0330","AN0333","AN0344","AN0369","AN0381","AN0391","AN0425","AN0495","AN0506","AN0522","AN0542","AN0557","AN0566","AN0601","AN0618","AN0650","AN0653","AN0689","AN0704","AN0734","AN0739","AN0752","AN0799","AN0800","AN0874","AN0877","AN0905","AN0924","AN0945","AN0964","AN0990","AN1014","AN1022","AN1059","AN1063","AN1066","AN1082","AN1099","AN1163","AN1167","AN1171","AN1191","AN1208","AN1218","AN1227","AN1244","AN1248","AN1251","AN1296","AN1316","AN1327","AN1355","AN1359","AN1368","AN1383","AN1391","AN1412","AN1415","AN1442","AN1478","AN1482","AN1533","AN1563","AN1585","AN1628","AN1635","AN1639","AN1643"],"techniques":["T1001.001","T1001.002","T1001.003","T1003","T1007","T1010","T1011","T1011.001","T1014","T1018","T1021","T1021.004","T1021.005","T1025","T1027","T1027.003","T1027.004","T1027.005","T1027.006","T1027.008","T1027.009","T1037","T1040","T1041","T1046","T1048","T1048.001","T1048.002","T1048.003","T1049","T1052","T1052.001","T1053","T1053.002","T1056","T1056.001","T1056.002","T1056.004","T1057","T1059.004","T1059.005","T1059.006","T1059.007","T1070","T1070.006","T1070.007","T1070.008","T1070.009","T1070.010","T1071","T1071.001","T1071.002","T1071.003","T1071.005","T1090.001","T1090.002","T1090.003","T1090.004","T1102","T1102.001","T1111","T1120","T1195","T1203","T1204","T1204.004","T1210","T1211","T1212","T1213","T1217","T1218","T1218.015","T1219","T1499.001","T1499.003","T1543.001","T1547.006","T1553","T1553.001","T1553.004","T1555.005","T1556","T1556.003","T1558.005","T1559","T1565","T1565.001","T1565.002","T1565.003","T1614","T1614.001","T1668","T1669"],"platforms":["macOS"],"kev_cves":["CVE-2009-4324","CVE-2010-2883","CVE-2013-0641","CVE-2013-3346","CVE-2014-6271","CVE-2014-7169","CVE-2015-3113","CVE-2015-5119","CVE-2016-10033","CVE-2017-6742","CVE-2018-4878","CVE-2018-4939","CVE-2018-4990","CVE-2019-0604","CVE-2019-0708","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-18935","CVE-2020-12812","CVE-2020-1472","CVE-2020-3580","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-21973","CVE-2021-22017","CVE-2021-22893","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-31207","CVE-2021-32030","CVE-2021-34473","CVE-2021-35394","CVE-2021-36380","CVE-2021-37975","CVE-2021-39144","CVE-2021-40449","CVE-2021-40539","CVE-2021-41773","CVE-2021-42013","CVE-2021-44077","CVE-2021-44515","CVE-2021-45382","CVE-2022-1040","CVE-2022-20699","CVE-2022-20700","CVE-2022-20701","CVE-2022-20703","CVE-2022-21999","CVE-2022-22948","CVE-2022-22963","CVE-2022-23748","CVE-2022-24086","CVE-2022-24682","CVE-2022-26500","CVE-2022-26501","CVE-2022-41128","CVE-2022-41328","CVE-2022-42475","CVE-2022-43769","CVE-2023-0669","CVE-2023-1389","CVE-2023-21608","CVE-2023-22515","CVE-2023-23397","CVE-2023-26360","CVE-2023-26369","CVE-2023-28252","CVE-2023-2868","CVE-2023-34048","CVE-2023-35078","CVE-2023-36844","CVE-2023-38035","CVE-2023-38831","CVE-2023-39780","CVE-2023-40044","CVE-2023-44221","CVE-2023-46604","CVE-2023-47565","CVE-2023-49897","CVE-2023-5631","CVE-2024-11120","CVE-2024-20353","CVE-2024-20359","CVE-2024-24919","CVE-2024-26169","CVE-2024-27443","CVE-2024-40890","CVE-2024-40891","CVE-2024-42009","CVE-2024-45195","CVE-2024-4577","CVE-2024-48248","CVE-2024-49035","CVE-2024-4978","CVE-2024-50302","CVE-2024-5274","CVE-2024-53150","CVE-2024-53704","CVE-2024-54085","CVE-2024-55550","CVE-2024-55591","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-24016","CVE-2025-24993","CVE-2025-25257","CVE-2025-27038","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31200","CVE-2025-31201","CVE-2025-32433","CVE-2025-3248","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-34028","CVE-2025-3935","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-48927","CVE-2025-48928","CVE-2025-5419","CVE-2025-54309","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"fs-fsevents","name":"fs:fsevents","channels":[{"channel":"Create in /Users/*/Downloads or /private/var/folders/* with quarantine attribute","analytics":["AN0180"],"data_components":["DC0039"]},{"channel":"Directory events (kFSEventStreamEventFlagItemCreated)","analytics":["AN1300"],"data_components":["DC0039"]},{"channel":"Extensions","analytics":["AN1063"],"data_components":["DC0061"]},{"channel":"create/write/rename under user-writable paths","analytics":["AN0799"],"data_components":["DC0061"]},{"channel":"file system events indicating access to system configuration files and environmental information sources","analytics":["AN1307"],"data_components":["DC0055"]},{"channel":"file system events indicating permission or attribute changes","analytics":["AN0836"],"data_components":["DC0059"]},{"channel":"file system events indicating permission, ownership, or extended attribute changes on critical paths. File system modification events with kFSEventStreamEventFlagItemChangeOwner, kFSEventStreamEventFlagItemXattrMod flags","analytics":["AN0999"],"data_components":["DC0061"]}],"data_components":["DC0039","DC0055","DC0059","DC0061"],"analytics":["AN0180","AN0799","AN0836","AN0999","AN1063","AN1300","AN1307"],"techniques":["T1014","T1080","T1203","T1204.001","T1222","T1222.002","T1480.001"],"platforms":["macOS"],"kev_cves":["CVE-2012-0767","CVE-2015-5119","CVE-2018-4939","CVE-2020-3580","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-37975","CVE-2021-39144","CVE-2022-20701","CVE-2022-20703","CVE-2022-21971","CVE-2022-22960","CVE-2022-23748","CVE-2022-24682","CVE-2022-3038","CVE-2022-3075","CVE-2022-41128","CVE-2022-43769","CVE-2023-2136","CVE-2023-21608","CVE-2023-23397","CVE-2023-26369","CVE-2023-34048","CVE-2023-36844","CVE-2023-47565","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2024-11120","CVE-2024-26169","CVE-2024-38112","CVE-2024-45195","CVE-2024-5274","CVE-2025-24016","CVE-2025-24993","CVE-2025-27038","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31200","CVE-2025-31201","CVE-2025-3248","CVE-2025-3935","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-5419","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"azure-audit","name":"azure:audit","channels":[{"channel":"Add delegated admin / Assign admin roles / Update application consent","analytics":["AN1347"],"data_components":["DC0088"]},{"channel":"Add member to role","analytics":["AN0899"],"data_components":["DC0010"]},{"channel":"Add service principal credentials, app password added, app role assignment","analytics":["AN1469"],"data_components":["DC0010"]},{"channel":"Add user","analytics":["AN0899","AN1079","AN1607"],"data_components":["DC0014"]},{"channel":"App registrations or consent grants by abnormal users or at unusual times","analytics":["AN1425"],"data_components":["DC0038"]},{"channel":"Consent to application: OAuth application consent granted to service principal","analytics":["AN1487"],"data_components":["DC0069"]},{"channel":"ListApplications, ListServicePrincipals: Large-scale queries against identity or application objects","analytics":["AN1128"],"data_components":["DC0083"]},{"channel":"New device object creation","analytics":["AN0103"],"data_components":["DC0087"]},{"channel":"Operation IN (\"Add device\", \"Add registered users to device\", \"Add registered owner to device\")","analytics":["AN0103"],"data_components":["DC0010"]},{"channel":"Rename user","analytics":["AN1079"],"data_components":["DC0010"]},{"channel":"operation contains 'Get*Password*Policy' OR 'List*Authentication*Policy' OR 'Get-ADDefaultDomainPasswordPolicy'","analytics":["AN0459"],"data_components":["DC0013"]}],"data_components":["DC0010","DC0013","DC0014","DC0038","DC0069","DC0083","DC0087","DC0088"],"analytics":["AN0103","AN0459","AN0899","AN1079","AN1128","AN1347","AN1425","AN1469","AN1487","AN1607"],"techniques":["T1036.010","T1098.001","T1098.005","T1136","T1136.003","T1199","T1201","T1526","T1528","T1671"],"platforms":["Identity Provider","Office Suite"],"kev_cves":["CVE-2021-34473","CVE-2021-40539","CVE-2021-44077","CVE-2023-20198","CVE-2023-22515","CVE-2023-27997","CVE-2023-28252","CVE-2023-34362","CVE-2023-35078","CVE-2024-38475","CVE-2024-53704","CVE-2025-31161"]},{"slug":"saas-okta","name":"saas:okta","channels":[{"channel":"Conditional Access policy rule modified or MFA requirement disabled","analytics":["AN0088"],"data_components":["DC0038"]},{"channel":"Federation configuration update or signing certificate change","analytics":["AN0818"],"data_components":["DC0038"]},{"channel":"MFAChallengeIssued","analytics":["AN0453"],"data_components":["DC0038"]},{"channel":"Sign-in logs / audit events","analytics":["AN1546"],"data_components":["DC0002"]},{"channel":"System API Call: user.read, group.read","analytics":["AN1090"],"data_components":["DC0038"]},{"channel":"Unusual OAuth app requesting message-read scopes for Slack/Teams/Jira","analytics":["AN0310"],"data_components":["DC0002"]},{"channel":"User Attribute Modified / Role Assignment Changed","analytics":["AN0268"],"data_components":["DC0010"]},{"channel":"User Enumeration Events","analytics":["AN1616"],"data_components":["DC0013"]},{"channel":"User lifecycle events","analytics":["AN1079"],"data_components":["DC0013"]},{"channel":"WebUI access to administrator dashboard","analytics":["AN0809"],"data_components":["DC0038"]},{"channel":"policy.rule.update;system.log.disable;admin.role.assign","analytics":["AN2042"],"data_components":["DC0038"]},{"channel":"session.impersonation.start","analytics":["AN0202"],"data_components":["DC0002"]},{"channel":"session.token.reuse","analytics":["AN1406"],"data_components":["DC0067"]},{"channel":"user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize","analytics":["AN2034"],"data_components":["DC0002"]},{"channel":"user.authentication.sso","analytics":["AN1503"],"data_components":["DC0088"]},{"channel":"user.lifecycle.delete, user.account.lock","analytics":["AN0339"],"data_components":["DC0010"]},{"channel":"user.session.start","analytics":["AN0809"],"data_components":["DC0067"]}],"data_components":["DC0002","DC0010","DC0013","DC0038","DC0067","DC0088"],"analytics":["AN0088","AN0202","AN0268","AN0310","AN0339","AN0453","AN0809","AN0818","AN1079","AN1090","AN1406","AN1503","AN1546","AN1616","AN2034","AN2042"],"techniques":["T1036.010","T1078","T1078.004","T1087","T1087.004","T1098","T1531","T1538","T1539","T1550.004","T1552.008","T1556.007","T1556.009","T1621","T1684","T1687"],"platforms":["Identity Provider","SaaS"],"kev_cves":["CVE-2012-0767","CVE-2019-11634","CVE-2019-13608","CVE-2021-20035","CVE-2021-22894","CVE-2021-22899","CVE-2021-32030","CVE-2021-36934","CVE-2021-41379","CVE-2021-42321","CVE-2021-44515","CVE-2022-1040","CVE-2022-20701","CVE-2022-21919","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-23131","CVE-2022-24521","CVE-2022-26500","CVE-2022-26904","CVE-2022-37969","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2023-20109","CVE-2023-20118","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-21674","CVE-2023-22515","CVE-2023-22952","CVE-2023-23397","CVE-2023-27524","CVE-2023-27532","CVE-2023-28229","CVE-2023-28252","CVE-2023-34362","CVE-2023-39780","CVE-2023-41179","CVE-2023-46805","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20359","CVE-2024-20399","CVE-2024-21893","CVE-2024-37085","CVE-2024-53704","CVE-2024-55591","CVE-2024-57968","CVE-2025-24016","CVE-2025-31161"]},{"slug":"networkdevice-syslog","name":"networkdevice:syslog","channels":[{"channel":"AAA or TACACS authentication failures","analytics":["AN1340"],"data_components":["DC0002"]},{"channel":"AAA, RADIUS, or TACACS authentication","analytics":["AN1267"],"data_components":["DC0002"]},{"channel":"ACL/Firewall rule modification or new route injection","analytics":["AN0015"],"data_components":["DC0085"]},{"channel":"Admin activity","analytics":["AN0099"],"data_components":["DC0034"]},{"channel":"Authentication failures or unusual community string usage in SNMP queries","analytics":["AN1630"],"data_components":["DC0085"]},{"channel":"Authentication failures, unexpected community string usage, or unauthorized SNMPv1/v2 requests","analytics":["AN1249"],"data_components":["DC0085"]},{"channel":"Boot information log showing image loaded from TFTP server instead of local storage","analytics":["AN1603"],"data_components":["DC0004"]},{"channel":"CLI Command Audit","analytics":["AN1084"],"data_components":["DC0064"]},{"channel":"CLI Command Logging","analytics":["AN1044"],"data_components":["DC0064"]},{"channel":"CLI command audit","analytics":["AN0471"],"data_components":["DC0064"]},{"channel":"Command Audit / Configuration Change","analytics":["AN0136"],"data_components":["DC0064"]},{"channel":"Config change: CLI/NETCONF/SNMP – 'monitor session', 'mirror port'","analytics":["AN1132"],"data_components":["DC0078"]},{"channel":"Config/ACL changes, line vty transport input changes, telnet/ssh/http(s) enable, image/feature module changes.","analytics":["AN0845"],"data_components":["DC0078"]},{"channel":"Config/ACL/line vty changes, service enable (telnet/ssh/http(s)), module reloads","analytics":["AN1451"],"data_components":["DC0078"]},{"channel":"Custom firmware or routing changes","analytics":["AN1024"],"data_components":["DC0004"]},{"channel":"Detected CLI command to export key material","analytics":["AN1519"],"data_components":["DC0064"]},{"channel":"Dynamic route changes","analytics":["AN0926"],"data_components":["DC0082"]},{"channel":"Failed and successful logins to network devices outside approved admin IP ranges","analytics":["AN0647"],"data_components":["DC0002"]},{"channel":"Failed authentication requests redirected to non-standard portals","analytics":["AN1069"],"data_components":["DC0038"]},{"channel":"Image Upgrade / Configuration Change","analytics":["AN0246"],"data_components":["DC0004"]},{"channel":"OS version query results inconsistent with expected or approved version list","analytics":["AN1570"],"data_components":["DC0059"]},{"channel":"Privilege-level command execution","analytics":["AN1457"],"data_components":["DC0064"]},{"channel":"Privileged login followed by destructive command sequence","analytics":["AN0885"],"data_components":["DC0002"]},{"channel":"Privileged login followed by destructive format command","analytics":["AN0830"],"data_components":["DC0002"]},{"channel":"SIP REGISTER, INVITE, or unusual call destination metadata","analytics":["AN0684"],"data_components":["DC0038"]},{"channel":"System reboot scheduled or performed","analytics":["AN1542"],"data_components":["DC0018"]},{"channel":"Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance","analytics":["AN0497"],"data_components":["DC0021"]},{"channel":"User privilege escalation to level 15/root prior to destructive commands","analytics":["AN0387"],"data_components":["DC0002"]},{"channel":"aaa privilege_exec","analytics":["AN0257"],"data_components":["DC0021"]},{"channel":"admin login events","analytics":["AN0879"],"data_components":["DC0002"]},{"channel":"authentication & authorization","analytics":["AN1432"],"data_components":["DC0002"]},{"channel":"authentication logs","analytics":["AN1287"],"data_components":["DC0002"]},{"channel":"authorization/accounting logs","analytics":["AN0399"],"data_components":["DC0002"]},{"channel":"cmd='show aaa*' OR 'show running-config | include password|aaa' OR 'show aaa common-criteria policy all'","analytics":["AN0461"],"data_components":["DC0064"]},{"channel":"command audit","analytics":["AN1219"],"data_components":["DC0064"]},{"channel":"command sequence: erase → format → reload","analytics":["AN0936"],"data_components":["DC0064"]},{"channel":"command-exec: CLI commands containing \"show clock\", \"show clock detail\", \"show timezone\" executed by suspicious user/source","analytics":["AN0434"],"data_components":["DC0064"]},{"channel":"command_exec","analytics":["AN0399"],"data_components":["DC0064"]},{"channel":"config","analytics":["AN0315"],"data_components":["DC0061"]},{"channel":"config access, authentication logs","analytics":["AN0296"],"data_components":["DC0002"]},{"channel":"config change (e.g., logging buffered, pcap buffers)","analytics":["AN0879"],"data_components":["DC0085"]},{"channel":"config push events","analytics":["AN0627"],"data_components":["DC0038"]},{"channel":"eventlog","analytics":["AN0257"],"data_components":["DC0064"]},{"channel":"exec command='monitor capture'","analytics":["AN0879"],"data_components":["DC0064"]},{"channel":"flow records","analytics":["AN0427"],"data_components":["DC0078"]},{"channel":"login failed","analytics":["AN1525"],"data_components":["DC0002"]},{"channel":"no logging buffered, no aaa new-model, disable firewall","analytics":["AN0893"],"data_components":["DC0064"]},{"channel":"no logging host, no aaa new-model, no snmp-server, commit","analytics":["AN1374"],"data_components":["DC0018"]},{"channel":"reload command issued","analytics":["AN1542"],"data_components":["DC0064"]},{"channel":"startup-config","analytics":["AN0661"],"data_components":["DC0061"]},{"channel":"syslog facility LOCAL7 or trap messages","analytics":["AN1587"],"data_components":["DC0064"]},{"channel":"system boot logs","analytics":["AN0661"],"data_components":["DC0064"]},{"channel":"username <user> privilege <level>","analytics":["AN1240"],"data_components":["DC0014"]}],"data_components":["DC0002","DC0004","DC0014","DC0018","DC0021","DC0034","DC0038","DC0059","DC0061","DC0064","DC0078","DC0082","DC0085"],"analytics":["AN0015","AN0099","AN0136","AN0246","AN0257","AN0296","AN0315","AN0387","AN0399","AN0427","AN0434","AN0461","AN0471","AN0497","AN0627","AN0647","AN0661","AN0684","AN0830","AN0845","AN0879","AN0885","AN0893","AN0926","AN0936","AN1024","AN1044","AN1069","AN1084","AN1132","AN1219","AN1240","AN1249","AN1267","AN1287","AN1340","AN1374","AN1432","AN1451","AN1457","AN1519","AN1525","AN1542","AN1570","AN1587","AN1603","AN1630"],"techniques":["T1018","T1020.001","T1033","T1037","T1037.004","T1040","T1048.003","T1056.001","T1057","T1059","T1059.004","T1059.008","T1070.003","T1070.007","T1070.010","T1072","T1078.001","T1082","T1083","T1090.002","T1090.003","T1110.001","T1110.002","T1110.003","T1110.004","T1124","T1136.001","T1201","T1205","T1205.001","T1490","T1529","T1542.004","T1542.005","T1552.004","T1557.004","T1561","T1561.001","T1561.002","T1566.004","T1599","T1601.002","T1602","T1602.001","T1602.002","T1685"],"platforms":["Linux","Network Devices"],"kev_cves":["CVE-2010-2883","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-11882","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-6789","CVE-2018-7600","CVE-2019-0708","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-19781","CVE-2019-3398","CVE-2020-0787","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3580","CVE-2020-5902","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21972","CVE-2021-22005","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-27101","CVE-2021-27102","CVE-2021-27104","CVE-2021-31166","CVE-2021-3129","CVE-2021-32030","CVE-2021-34473","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-40449","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-45046","CVE-2021-45382","CVE-2022-1040","CVE-2022-20699","CVE-2022-20700","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22947","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24521","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-41125","CVE-2022-41328","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2022-47966","CVE-2023-20109","CVE-2023-20118","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-2533","CVE-2023-26359","CVE-2023-27350","CVE-2023-28252","CVE-2023-2868","CVE-2023-33246","CVE-2023-33538","CVE-2023-34192","CVE-2023-34362","CVE-2023-35081","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-39780","CVE-2023-40044","CVE-2023-41179","CVE-2023-43770","CVE-2023-44221","CVE-2023-46604","CVE-2023-48365","CVE-2023-48788","CVE-2023-7101","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-20353","CVE-2024-20359","CVE-2024-20399","CVE-2024-20953","CVE-2024-21413","CVE-2024-21887","CVE-2024-23692","CVE-2024-24919","CVE-2024-26169","CVE-2024-27198","CVE-2024-27443","CVE-2024-29059","CVE-2024-34102","CVE-2024-38475","CVE-2024-41710","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-4879","CVE-2024-4885","CVE-2024-4947","CVE-2024-50603","CVE-2024-5217","CVE-2024-53104","CVE-2024-53197","CVE-2024-53704","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0282","CVE-2025-0994","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21391","CVE-2025-21590","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-25257","CVE-2025-27038","CVE-2025-30397","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-53770","CVE-2025-6543","CVE-2025-6554"]},{"slug":"macos-cron","name":"macos:cron","channels":[{"channel":"cron/launchd","analytics":["AN1115"],"data_components":["DC0001"]}],"data_components":["DC0001"],"analytics":["AN1115"],"techniques":["T1020"],"platforms":["macOS"],"kev_cves":[]},{"slug":"kubernetes-apiserver","name":"kubernetes:apiserver","channels":[{"channel":"Pod spec with hostPath or privileged securityContext","analytics":["AN0612"],"data_components":["DC0092"]},{"channel":"Resource creation and update logs","analytics":["AN0986"],"data_components":["DC0028"]},{"channel":"authentication.k8s.io/v1beta1","analytics":["AN1268"],"data_components":["DC0002"]},{"channel":"create/exec: Kubernetes API calls to exec into containers or create pods from curl, kubectl, or SDK clients","analytics":["AN0233"],"data_components":["DC0072"]},{"channel":"exec into pod followed by secret retrieval via API","analytics":["AN0571"],"data_components":["DC0032"]},{"channel":"get/list requests to /api/v1/secrets or /api/v1/namespaces/*/serviceaccounts","analytics":["AN0571"],"data_components":["DC0002"]},{"channel":"kubectl exec or kubelet API calls targeting running pods","analytics":["AN0177"],"data_components":["DC0032"]},{"channel":"list or get requests against pods, deployments, or nodes","analytics":["AN1352"],"data_components":["DC0037"]},{"channel":"serviceAccount token used in API requests not tied to workload identity","analytics":["AN0530"],"data_components":["DC0007"]},{"channel":"verb=create, resource=cronjobs, group=batch","analytics":["AN0582"],"data_components":["DC0001"]}],"data_components":["DC0001","DC0002","DC0007","DC0028","DC0032","DC0037","DC0072","DC0092"],"analytics":["AN0177","AN0233","AN0530","AN0571","AN0582","AN0612","AN0986","AN1268","AN1352"],"techniques":["T1036.005","T1053.007","T1059.013","T1110.004","T1550.001","T1552.007","T1609","T1611","T1613"],"platforms":["Containers"],"kev_cves":["CVE-2023-26360","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226"]},{"slug":"m365-unified","name":"m365:unified","channels":[{"channel":"Abnormal user claims or unexpected elevated role assignment in SAML assertion","analytics":["AN0421"],"data_components":["DC0088"]},{"channel":"Accessed SharePoint files or pages","analytics":["AN1160"],"data_components":["DC0025"]},{"channel":"Add app role assignment grant to user: Consent to application by privileged or unexpected accounts","analytics":["AN1487"],"data_components":["DC0066"]},{"channel":"Add member to group","analytics":["AN0902"],"data_components":["DC0094"]},{"channel":"Add member to role, Set-Mailbox","analytics":["AN0773"],"data_components":["DC0010"]},{"channel":"Add user","analytics":["AN0902"],"data_components":["DC0014"]},{"channel":"Add-DelegatedAdmin, Set-PartnerOfRecord, Add-MailboxPermission, Set-OrganizationRelationship","analytics":["AN1350"],"data_components":["DC0038"]},{"channel":"Add-MailboxPermission or Set-ManagementRoleAssignment","analytics":["AN1107"],"data_components":["DC0038"]},{"channel":"Add-MailboxPermission, UpdateFolderPermissions","analytics":["AN1051"],"data_components":["DC0010"]},{"channel":"AddFlow / UpdateFlow: New automation or workflow creation events","analytics":["AN1054"],"data_components":["DC0069"]},{"channel":"Admin Activity > Role Change or Sharing Change","analytics":["AN0270"],"data_components":["DC0010"]},{"channel":"AnonymousLinkCreated","analytics":["AN1581"],"data_components":["DC0027"]},{"channel":"App-only or delegated access patterns where client_id != known enterprise apps","analytics":["AN1426"],"data_components":["DC0025"]},{"channel":"Application Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise","analytics":["AN0501"],"data_components":["DC0038"]},{"channel":"ApplicationModified, ConsentGranted: Unexpected app consent or modification events linked to security evasion","analytics":["AN1637"],"data_components":["DC0038"]},{"channel":"Automated forwarding or file sync initiated by a logic app","analytics":["AN0028"],"data_components":["DC0064"]},{"channel":"Bulk downloads or API extractions from Microsoft-hosted data repositories (e.g., Dynamics 365)","analytics":["AN0680"],"data_components":["DC0055"]},{"channel":"ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA","analytics":["AN0496"],"data_components":["DC0038"]},{"channel":"Creation of Power Automate flow triggered by OneDrive or Exchange event","analytics":["AN0028"],"data_components":["DC0069"]},{"channel":"Creation or modification of inbox rule outside of normal user behavior","analytics":["AN0264"],"data_components":["DC0038"]},{"channel":"Delegated permission grants without user login event","analytics":["AN0527"],"data_components":["DC0002"]},{"channel":"Detection of hidden macro streams or SetHiddenAttribute actions","analytics":["AN1388"],"data_components":["DC0038"]},{"channel":"FileAccessed","analytics":["AN1581"],"data_components":["DC0038"]},{"channel":"FileAccessed, FileDownloaded, ConsentGranted","analytics":["AN1329"],"data_components":["DC0025"]},{"channel":"FileAccessed, FileDownloaded, SearchQueried","analytics":["AN1380"],"data_components":["DC0038"]},{"channel":"FileAccessed, MailboxAccessed","analytics":["AN0019"],"data_components":["DC0055"]},{"channel":"FileAccessed, SharingSet","analytics":["AN1505"],"data_components":["DC0088"]},{"channel":"FileAccessed: Access of email attachments by Office applications","analytics":["AN0191"],"data_components":["DC0038"]},{"channel":"FileUploaded or FileCopied events","analytics":["AN1514"],"data_components":["DC0038"]},{"channel":"FileUploaded, FileAccessed","analytics":["AN1301"],"data_components":["DC0102"]},{"channel":"Folder configuration updated with external or HTML-formatted Home Page via Set-MailboxFolder","analytics":["AN0503"],"data_components":["DC0038"]},{"channel":"GAL Lookup or Address Book download","analytics":["AN0642"],"data_components":["DC0038"]},{"channel":"Get-MsolServicePrincipal, ListAppRoles: Service discovery operations executed by accounts not normally performing administrative tasks","analytics":["AN1129"],"data_components":["DC0083"]},{"channel":"MacroSecuritySettingsChanged or SafeModeDisabled","analytics":["AN0894"],"data_components":["DC0063"]},{"channel":"MailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSet","analytics":["AN2033"],"data_components":["DC0038"]},{"channel":"MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams","analytics":["AN1365"],"data_components":["DC0038"]},{"channel":"MessageSend, MessageRead, or FileAttached events containing credential-like patterns","analytics":["AN0309"],"data_components":["DC0038"]},{"channel":"Modify Federation Settings or Update Authentication Policy","analytics":["AN0817"],"data_components":["DC0038"]},{"channel":"New agent registration by non-admin user","analytics":["AN0815"],"data_components":["DC0010"]},{"channel":"New-InboxRule or Set-InboxRule events recorded in Exchange Online","analytics":["AN0551"],"data_components":["DC0038"]},{"channel":"New-InboxRule, Set-InboxRule","analytics":["AN1591"],"data_components":["DC0070"]},{"channel":"Non-standard Office startup component detected (e.g., unexpected DLL path)","analytics":["AN0881"],"data_components":["DC0016"]},{"channel":"OAuthTokenIssued, FileAccessed, MailItemsAccessed","analytics":["AN0529"],"data_components":["DC0007"]},{"channel":"PowerShell: Add-MailboxPermission","analytics":["AN1052"],"data_components":["DC0038"]},{"channel":"PurgeAuditLogs, Remove-MailboxAuditLog","analytics":["AN0525"],"data_components":["DC0038"]},{"channel":"Read-only configuration review from GUI","analytics":["AN0810"],"data_components":["DC0038"]},{"channel":"Remove-Mailbox, Set-Mailbox","analytics":["AN0338"],"data_components":["DC0009"]},{"channel":"RunMacro","analytics":["AN1405"],"data_components":["DC0038"]},{"channel":"Scripted Activity","analytics":["AN1619"],"data_components":["DC0029"]},{"channel":"Search-Mailbox, Get-MessageTrace, eDiscovery requests","analytics":["AN0132"],"data_components":["DC0064"]},{"channel":"Send/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment types","analytics":["AN0188"],"data_components":["DC0038"]},{"channel":"Send/Receive: Inbound emails containing embedded or shortened URLs","analytics":["AN0298"],"data_components":["DC0038"]},{"channel":"Send/Receive: Inbound emails with attachments from suspicious or spoofed senders","analytics":["AN0655"],"data_components":["DC0038"]},{"channel":"Send/Receive: Unusual spikes in inbound messages to a single recipient","analytics":["AN1008"],"data_components":["DC0038"]},{"channel":"SendMessage","analytics":["AN0746"],"data_components":["DC0069"]},{"channel":"SendOnBehalf, MessageSend, AttachmentPreviewed","analytics":["AN0151"],"data_components":["DC0038"]},{"channel":"SendOnBehalf, MessageSend, ClickThrough, MailItemsAccessed","analytics":["AN0147"],"data_components":["DC0038"]},{"channel":"SendOnBehalf/SendAs: Emails sent where the sending identity mismatches account ownership","analytics":["AN0792"],"data_components":["DC0038"]},{"channel":"SendOnBehalf/SendAs: Office Suite initiated messages using impersonated identities","analytics":["AN0796"],"data_components":["DC0038"]},{"channel":"Session activity without correlated login event","analytics":["AN0487"],"data_components":["DC0007"]},{"channel":"Session creation without MFA or login event","analytics":["AN0722"],"data_components":["DC0006"]},{"channel":"SessionId reused from different device/browser fingerprint","analytics":["AN0202"],"data_components":["DC0007"]},{"channel":"Set federation settings on domain|Set domain authentication|Add federated identity provider","analytics":["AN0756","AN1260"],"data_components":["DC0038"]},{"channel":"Set-ADUser OR Set-ADAccountControl","analytics":["AN0290"],"data_components":["DC0010"]},{"channel":"Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication","analytics":["AN2042"],"data_components":["DC0038"]},{"channel":"Set-CsOnlineUser or UpdateAuthPolicy","analytics":["AN0549"],"data_components":["DC0038"]},{"channel":"Set-Mailbox, Add-InboxRule, RegisterWebhook","analytics":["AN0440"],"data_components":["DC0038"]},{"channel":"Set-Mailbox, New-InboxRule","analytics":["AN1312"],"data_components":["DC0064"]},{"channel":"Set-Mailbox, Set-AppPassword, Add-MailboxPermission","analytics":["AN1471"],"data_components":["DC0066"]},{"channel":"Set-Mailbox, Set-InboxRule, Set-MailboxFolderPermission","analytics":["AN1117"],"data_components":["DC0010"]},{"channel":"Set-Mailbox, Set-MailboxPolicy, Set-TrustedLocation","analytics":["AN1437"],"data_components":["DC0064"]},{"channel":"Set-MailboxAuditBypassAssociation or disabling Advanced Auditing","analytics":["AN0803"],"data_components":["DC0010"]},{"channel":"Set-PartnerOfRecord / CompanyAdministrator role assignments / New-DelegatedAdminRelationship","analytics":["AN1347"],"data_components":["DC0038"]},{"channel":"SharingSet","analytics":["AN1581"],"data_components":["DC0023"]},{"channel":"Sign-in logs","analytics":["AN1279"],"data_components":["DC0002"]},{"channel":"TeamsMessagesAccessedViaEDiscovery, TeamsGraphMessageExport","analytics":["AN1566"],"data_components":["DC0038"]},{"channel":"TokenIssued, FileAccessed","analytics":["AN0959"],"data_components":["DC0007"]},{"channel":"Transport rule or inbox rule creation events","analytics":["AN0554"],"data_components":["DC0038"]},{"channel":"Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call","analytics":["AN0686"],"data_components":["DC0038"]},{"channel":"Unusual form activity within Outlook client, including load of non-default forms","analytics":["AN0086"],"data_components":["DC0038"]},{"channel":"User excluded from MFA or MFA method registered","analytics":["AN0544"],"data_components":["DC0010"]},{"channel":"UserLoggedIn","analytics":["AN0019","AN0203"],"data_components":["DC0067"]},{"channel":"ViewAdminReport","analytics":["AN0810"],"data_components":["DC0067"]},{"channel":"Workload=AzureActiveDirectory OR Exchange AND (Operation=Cmdlet AND Parameters contains 'Password' AND (CmdletName='Get-*' OR CmdletName='Get-OrganizationConfig'))","analytics":["AN0460"],"data_components":["DC0013"]},{"channel":"certificate added or modified in application credentials","analytics":["AN0674"],"data_components":["DC0038"]},{"channel":"login using refresh_token with no preceding authentication context","analytics":["AN0956"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0006","DC0007","DC0009","DC0010","DC0013","DC0014","DC0016","DC0023","DC0025","DC0027","DC0029","DC0038","DC0055","DC0063","DC0064","DC0066","DC0067","DC0069","DC0070","DC0083","DC0088","DC0094","DC0102"],"analytics":["AN0019","AN0028","AN0086","AN0132","AN0147","AN0151","AN0188","AN0191","AN0202","AN0203","AN0264","AN0270","AN0290","AN0298","AN0309","AN0338","AN0421","AN0440","AN0460","AN0487","AN0496","AN0501","AN0503","AN0525","AN0527","AN0529","AN0544","AN0549","AN0551","AN0554","AN0642","AN0655","AN0674","AN0680","AN0686","AN0722","AN0746","AN0756","AN0773","AN0792","AN0796","AN0803","AN0810","AN0815","AN0817","AN0881","AN0894","AN0902","AN0956","AN0959","AN1008","AN1051","AN1052","AN1054","AN1107","AN1117","AN1129","AN1160","AN1260","AN1279","AN1301","AN1312","AN1329","AN1347","AN1350","AN1365","AN1380","AN1388","AN1405","AN1426","AN1437","AN1471","AN1487","AN1505","AN1514","AN1566","AN1581","AN1591","AN1619","AN1637","AN2033","AN2042"],"techniques":["T1021.007","T1070","T1078.004","T1080","T1087","T1087.003","T1098","T1098.001","T1098.002","T1098.003","T1110","T1114","T1114.002","T1114.003","T1136.003","T1137","T1137.001","T1137.002","T1137.003","T1137.004","T1137.005","T1189","T1199","T1201","T1211","T1212","T1213","T1213.002","T1213.005","T1213.006","T1484","T1484.002","T1496","T1526","T1528","T1530","T1531","T1534","T1537","T1538","T1539","T1546","T1548.005","T1550","T1550.001","T1550.004","T1552.008","T1556","T1556.006","T1556.007","T1564","T1564.008","T1566","T1566.001","T1566.002","T1566.004","T1567","T1567.004","T1606","T1606.001","T1606.002","T1648","T1649","T1657","T1667","T1671","T1684","T1684.001","T1685.002","T1687"],"platforms":["Identity Provider","Office Suite","SaaS","Windows"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-0767","CVE-2012-2034","CVE-2012-5054","CVE-2013-0640","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2017-11292","CVE-2017-11882","CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-0688","CVE-2020-12812","CVE-2020-1472","CVE-2020-8193","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-32030","CVE-2021-35394","CVE-2021-40449","CVE-2021-44228","CVE-2021-44515","CVE-2021-45382","CVE-2022-21999","CVE-2022-22948","CVE-2022-24086","CVE-2022-29303","CVE-2022-29464","CVE-2022-34713","CVE-2022-41033","CVE-2022-41082","CVE-2022-41128","CVE-2023-1389","CVE-2023-22527","CVE-2023-22952","CVE-2023-2533","CVE-2023-27532","CVE-2023-2868","CVE-2023-32315","CVE-2023-34362","CVE-2023-35078","CVE-2023-36884","CVE-2023-38035","CVE-2023-43770","CVE-2023-47565","CVE-2023-49897","CVE-2023-7024","CVE-2024-11182","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-21413","CVE-2024-23692","CVE-2024-27443","CVE-2024-38112","CVE-2024-38475","CVE-2024-42009","CVE-2024-4671","CVE-2024-49035","CVE-2024-4947","CVE-2024-5274","CVE-2024-53704","CVE-2025-0411","CVE-2025-24054","CVE-2025-24201","CVE-2025-33053","CVE-2025-4632","CVE-2025-48927","CVE-2025-48928","CVE-2025-5419","CVE-2025-54309","CVE-2025-6554","CVE-2025-6558"]},{"slug":"m365-office","name":"m365:office","channels":[{"channel":"Anomalous editing of invoice or payment document templates","analytics":["AN1365"],"data_components":["DC0061"]},{"channel":"External HTTP/DNS connection from Office binary shortly after macro trigger","analytics":["AN0029"],"data_components":["DC0085"]},{"channel":"Startup execution includes non-default component","analytics":["AN0881"],"data_components":["DC0064"]},{"channel":"VBA auto_open, auto_close, or document_open events","analytics":["AN0029"],"data_components":["DC0029"]}],"data_components":["DC0029","DC0061","DC0064","DC0085"],"analytics":["AN0029","AN0881","AN1365"],"techniques":["T1137.002","T1546","T1657"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"saas-integration","name":"saas:integration","channels":[{"channel":"New or modified third-party application integrations with elevated permissions","analytics":["AN1488"],"data_components":["DC0069"]}],"data_components":["DC0069"],"analytics":["AN1488"],"techniques":["T1671"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"saas-audit","name":"saas:audit","channels":[{"channel":"Application added or consent granted: Integration persisting after original user disabled","analytics":["AN1488"],"data_components":["DC0038"]},{"channel":"Log export integration removed or disabled","analytics":["AN0804"],"data_components":["DC0090"]},{"channel":"Repeated requests to SMS-generating endpoints using anomalous or new user agents, IP ranges, or geographies.","analytics":["AN0443"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0038","DC0090"],"analytics":["AN0443","AN0804","AN1488"],"techniques":["T1496.003","T1671","T1685.002"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"saas-github","name":"saas:github","channels":[{"channel":"Artifact generated includes base64/encoded exfil payload or URL","analytics":["AN1473"],"data_components":["DC0025"]},{"channel":"Bulk access to multiple files or large volume of repo requests within short time window","analytics":["AN0732"],"data_components":["DC0038"]},{"channel":"CI/CD secret accessed or exported","analytics":["AN1473"],"data_components":["DC0070"]},{"channel":"Login from unusual IP, device fingerprint, or location; access token creation from new client","analytics":["AN0732"],"data_components":["DC0067"]},{"channel":"Workflow triggered via pull_request_target from forked repo","analytics":["AN1473"],"data_components":["DC0069"]},{"channel":"repo.download, repo.clone, oauth.authorize, repo.getContent","analytics":["AN0732"],"data_components":["DC0070"]}],"data_components":["DC0025","DC0038","DC0067","DC0069","DC0070"],"analytics":["AN0732","AN1473"],"techniques":["T1213.003","T1677"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"saas-repoevents","name":"saas:RepoEvents","channels":[{"channel":"New file added or modified in PR targeting CI/CD or build config (e.g., `gitlab-ci.yml`, `build.gradle`, `pom.xml`, `.github/workflows/*.yml`)","analytics":["AN1473"],"data_components":["DC0059"]}],"data_components":["DC0059"],"analytics":["AN1473"],"techniques":["T1677"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"saas-prmetadata","name":"saas:PRMetadata","channels":[{"channel":"Commit message or branch name contains encoded strings or payload indicators","analytics":["AN1473"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN1473"],"techniques":["T1677"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"aws-vpcflowlogs","name":"AWS:VPCFlowLogs","channels":[{"channel":"High outbound traffic from new region resource","analytics":["AN0690"],"data_components":["DC0082"]},{"channel":"High volume internal-to-internal IP transfer or cross-account cloud transfer","analytics":["AN1580"],"data_components":["DC0085"]},{"channel":"Large outbound UDP traffic to multiple public reflector IPs","analytics":["AN1143"],"data_components":["DC0078"]},{"channel":"Large transfer volume (>20MB) from RDS IP range to external public IPs","analytics":["AN0679"],"data_components":["DC0082"]},{"channel":"Large volume of malformed or synthetic payloads to application endpoints prior to failure","analytics":["AN0853"],"data_components":["DC0085"]},{"channel":"Outbound connection to 169.254.169.254 from EC2 workload","analytics":["AN0001"],"data_components":["DC0082"]},{"channel":"Outbound connections to port 22, 3389","analytics":["AN0753"],"data_components":["DC0082"]},{"channel":"Outbound data flows","analytics":["AN0370"],"data_components":["DC0078"]},{"channel":"Outbound flow logs to known mining pools","analytics":["AN0744"],"data_components":["DC0078"]},{"channel":"Traffic between instances","analytics":["AN0198"],"data_components":["DC0085"]},{"channel":"Traffic observed on mirror destination instance","analytics":["AN1131"],"data_components":["DC0082"]},{"channel":"Unusual volume of data transferred from S3 storage endpoints to non-corporate IPs","analytics":["AN1328"],"data_components":["DC0085"]},{"channel":"Unusual volume of inbound packets from single source across short time interval","analytics":["AN0492"],"data_components":["DC0078"]},{"channel":"VPC/NSG flow logs for pod/instance egress to Internet or metadata","analytics":["AN0223"],"data_components":["DC0078"]},{"channel":"egress > 90th percentile or frequent connection reuse","analytics":["AN0084"],"data_components":["DC0078"]},{"channel":"source instance sends large volume of traffic in short window","analytics":["AN0972"],"data_components":["DC0078"]}],"data_components":["DC0078","DC0082","DC0085"],"analytics":["AN0001","AN0084","AN0198","AN0223","AN0370","AN0492","AN0679","AN0690","AN0744","AN0753","AN0853","AN0972","AN1131","AN1143","AN1328","AN1580"],"techniques":["T1020.001","T1021","T1048","T1074.002","T1190","T1213.006","T1496","T1496.002","T1498.001","T1498.002","T1499.002","T1499.004","T1530","T1535","T1537","T1552.005"],"platforms":["IaaS"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2013-0641","CVE-2014-6271","CVE-2014-7169","CVE-2015-3043","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-1472","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2020-8515","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29303","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-1389","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22527","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-28252","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-32315","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-49897","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-23692","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-45195","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-49035","CVE-2024-55550","CVE-2024-55591","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-27363","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-54309","CVE-2025-5777"]},{"slug":"auditd-path","name":"auditd:PATH","channels":[{"channel":"/etc/passwd or /etc/group file write","analytics":["AN0266"],"data_components":["DC0061"]},{"channel":"Creation of files with extensions .sql, .csv, .sqlite, especially in user directories","analytics":["AN0676"],"data_components":["DC0039"]},{"channel":"New .py/.js/.sh files written to ~/.local/, ~/.cache/, or /tmp/ within 5 min of package install","analytics":["AN0698"],"data_components":["DC0039"]},{"channel":"PATH","analytics":["AN0312","AN0847","AN1041"],"data_components":["DC0055","DC0059"]},{"channel":"Read access to known backup software configuration files (e.g., /etc/rsnapshot.conf, /opt/veeam/config.ini)","analytics":["AN0241"],"data_components":["DC0055"]},{"channel":"WRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirs","analytics":["AN1367"],"data_components":["DC0039"]},{"channel":"creation of .so files in non-standard directories (e.g., /tmp, /home/*)","analytics":["AN1209"],"data_components":["DC0039"]},{"channel":"file path matches exclusion directories","analytics":["AN0140"],"data_components":["DC0059"]},{"channel":"file read","analytics":["AN1281"],"data_components":["DC0055"]},{"channel":"mount target path within /proc/*","analytics":["AN1196"],"data_components":["DC0039"]},{"channel":"odification of ~/.ssh/authorized_keys or credential files","analytics":["AN2037"],"data_components":["DC0061"]},{"channel":"open: Access to sensitive log files (/var/log/auth.log, /var/log/secure, /var/log/syslog)","analytics":["AN0706"],"data_components":["DC0055"]},{"channel":"write or create events on *.pth, sitecustomize.py, usercustomize.py in site-packages or dist-packages","analytics":["AN0713"],"data_components":["DC0061"]},{"channel":"write: File modifications to /etc/systemd/sleep.conf or related power configuration files","analytics":["AN1175"],"data_components":["DC0061"]}],"data_components":["DC0039","DC0055","DC0059","DC0061"],"analytics":["AN0140","AN0241","AN0266","AN0312","AN0676","AN0698","AN0706","AN0713","AN0847","AN1041","AN1175","AN1196","AN1209","AN1281","AN1367","AN2037"],"techniques":["T1016.002","T1037","T1083","T1087.001","T1098","T1204.005","T1213.006","T1219","T1518.002","T1546.018","T1564.012","T1564.013","T1574.006","T1653","T1654","T1684"],"platforms":["Linux"],"kev_cves":["CVE-2012-0767","CVE-2017-12637","CVE-2018-4878","CVE-2019-11510","CVE-2019-19781","CVE-2021-32030","CVE-2022-41328","CVE-2023-22952","CVE-2023-27532","CVE-2024-20353","CVE-2024-20359","CVE-2024-53704"]},{"slug":"applicationlog-api","name":"ApplicationLog:API","channels":[{"channel":"Docker/Kubernetes API access from external sources","analytics":["AN1007"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN1007"],"techniques":["T1133"],"platforms":["Containers"],"kev_cves":["CVE-2014-6271","CVE-2014-7169","CVE-2018-4939","CVE-2019-0708","CVE-2019-11510","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-1472","CVE-2020-25506","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-22986","CVE-2021-26855","CVE-2021-26857","CVE-2022-20699","CVE-2023-20269","CVE-2023-27532","CVE-2023-39780","CVE-2023-48365","CVE-2024-11120","CVE-2024-45195","CVE-2025-32756"]},{"slug":"kubernetes-audit","name":"kubernetes:audit","channels":[{"channel":"Failed login","analytics":["AN1341"],"data_components":["DC0002"]},{"channel":"GET or LIST requests to /var/run/secrets/kubernetes.io/serviceaccount/ followed by access to the Kubernetes API server","analytics":["AN1423"],"data_components":["DC0055"]},{"channel":"Shell process (e.g., /bin/sh, /bin/bash) spawned in a container without an interactive session attached (i.e., automation anomaly)","analytics":["AN0233"],"data_components":["DC0064"]},{"channel":"Unauthorized container creation or kubelet exec logs","analytics":["AN1007"],"data_components":["DC0088"]},{"channel":"authentication.k8s.io","analytics":["AN1547"],"data_components":["DC0002"]},{"channel":"create","analytics":["AN1304"],"data_components":["DC0019","DC0060"]},{"channel":"create or update events for RoleBinding or ClusterRoleBinding objects","analytics":["AN1579"],"data_components":["DC0010"]},{"channel":"create: Pod/Container created with image tag 'latest' or mutable tag; imagePullPolicy=Always; noDigest=true","analytics":["AN0691"],"data_components":["DC0072"]},{"channel":"kubectl delete or patch of security pods/admission controllers","analytics":["AN1373"],"data_components":["DC0041"]},{"channel":"process execution involving curl, grep, or awk on secrets","analytics":["AN0859"],"data_components":["DC0064"]},{"channel":"seccomp or AppArmor profile changes","analytics":["AN0889"],"data_components":["DC0041"]}],"data_components":["DC0002","DC0010","DC0019","DC0041","DC0055","DC0060","DC0064","DC0072","DC0088"],"analytics":["AN0233","AN0691","AN0859","AN0889","AN1007","AN1304","AN1341","AN1373","AN1423","AN1547","AN1579"],"techniques":["T1059.013","T1078","T1098.006","T1110.003","T1133","T1204.003","T1528","T1543.005","T1552.001","T1685"],"platforms":["Containers","Linux"],"kev_cves":["CVE-2014-6271","CVE-2014-7169","CVE-2018-4939","CVE-2019-0708","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-1472","CVE-2020-25506","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-22894","CVE-2021-22899","CVE-2021-22986","CVE-2021-26855","CVE-2021-26857","CVE-2021-36934","CVE-2021-41379","CVE-2021-42321","CVE-2022-1040","CVE-2022-20699","CVE-2022-20701","CVE-2022-21919","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-23131","CVE-2022-24521","CVE-2022-26138","CVE-2022-26500","CVE-2022-26904","CVE-2022-37969","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2023-20109","CVE-2023-20118","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-21674","CVE-2023-22515","CVE-2023-22952","CVE-2023-23397","CVE-2023-27524","CVE-2023-27532","CVE-2023-28229","CVE-2023-28252","CVE-2023-39780","CVE-2023-41179","CVE-2023-46805","CVE-2023-48365","CVE-2024-11120","CVE-2024-20359","CVE-2024-20399","CVE-2024-21893","CVE-2024-37085","CVE-2024-38475","CVE-2024-45195","CVE-2024-55591","CVE-2024-57727","CVE-2024-57968","CVE-2025-24016","CVE-2025-31161","CVE-2025-32756"]},{"slug":"wineventlog-application","name":"WinEventLog:Application","channels":[{"channel":"API call to AddMonitor invoked by non-installer process","analytics":["AN0580"],"data_components":["DC0021"]},{"channel":"Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events","analytics":["AN0498"],"data_components":["DC0038"]},{"channel":"CLR Assembly creation, loading, or modification logs via MSSQL CLR integration","analytics":["AN0511"],"data_components":["DC0016"]},{"channel":"EventCode=1000","analytics":["AN0540","AN0797","AN0850","AN1314"],"data_components":["DC0038"]},{"channel":"Exchange Transport Service loads unusual .NET assembly or errors upon transport agent execution","analytics":["AN0472"],"data_components":["DC0038"]},{"channel":"Exchange logs or header artifacts","analytics":["AN1309"],"data_components":["DC0038"]},{"channel":"High-frequency errors or hangs from resource-intensive application components (e.g., .NET, IIS, Office Suite)","analytics":["AN1165"],"data_components":["DC0038"]},{"channel":"Office Add-in load errors, abnormal loading context, or unsigned add-in warnings","analytics":["AN0138"],"data_components":["DC0038"]},{"channel":"Outlook errors loading or processing custom form templates","analytics":["AN0085"],"data_components":["DC0038"]},{"channel":"Outlook logs indicating failure to load or render HTML page in Home Page view","analytics":["AN0502"],"data_components":["DC0038"]},{"channel":"Outlook rule creation, form load, or homepage redirection","analytics":["AN1116"],"data_components":["DC0038"]},{"channel":"Outlook rule execution failure or abnormal rule execution context","analytics":["AN0263"],"data_components":["DC0038"]},{"channel":"SCCM, Intune logs","analytics":["AN0623"],"data_components":["DC0038"]},{"channel":"Service crash, unhandled exception, or application hang warnings for critical services (e.g., IIS, DNS, SQL Server)","analytics":["AN0584"],"data_components":["DC0038"]},{"channel":"Stored procedure creation, modification, or xp_cmdshell invocation via SQL logs or SQL Server auditing","analytics":["AN0511"],"data_components":["DC0029"]},{"channel":"Unexpected spikes in request volume, application-level errors, or thread pool exhaustion in web or API logs","analytics":["AN0489"],"data_components":["DC0038"]},{"channel":"Unexpected web application errors or CMS logs showing modification to index.html, default.aspx, or other public-facing files","analytics":["AN0662"],"data_components":["DC0038"]},{"channel":"Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs","analytics":["AN1507"],"data_components":["DC0038"]},{"channel":"VPN, Citrix, or remote access gateway logs showing external IP addresses","analytics":["AN1004"],"data_components":["DC0038"]},{"channel":"WMI Object Creation Events","analytics":["AN0973"],"data_components":["DC0008"]}],"data_components":["DC0008","DC0016","DC0021","DC0029","DC0038"],"analytics":["AN0085","AN0138","AN0263","AN0472","AN0489","AN0498","AN0502","AN0511","AN0540","AN0580","AN0584","AN0623","AN0662","AN0797","AN0850","AN0973","AN1004","AN1116","AN1165","AN1309","AN1314","AN1507"],"techniques":["T1027.005","T1027.011","T1072","T1114","T1133","T1137","T1137.003","T1137.004","T1137.005","T1137.006","T1189","T1203","T1204","T1491","T1499","T1499.002","T1499.003","T1499.004","T1505","T1505.001","T1505.002","T1547.010"],"platforms":["Office Suite","Windows"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2018-4939","CVE-2019-0708","CVE-2019-11510","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-0688","CVE-2020-1472","CVE-2020-25506","CVE-2020-5735","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-22986","CVE-2021-26855","CVE-2021-26857","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-35394","CVE-2021-37975","CVE-2021-39144","CVE-2021-45382","CVE-2022-20699","CVE-2022-20701","CVE-2022-20703","CVE-2022-23748","CVE-2022-26258","CVE-2022-29303","CVE-2022-41128","CVE-2022-43769","CVE-2023-20109","CVE-2023-20269","CVE-2023-21608","CVE-2023-23397","CVE-2023-26369","CVE-2023-27532","CVE-2023-34048","CVE-2023-36844","CVE-2023-38831","CVE-2023-39780","CVE-2023-43770","CVE-2023-44487","CVE-2023-47565","CVE-2023-48365","CVE-2023-49897","CVE-2023-6549","CVE-2023-7024","CVE-2024-11120","CVE-2024-26169","CVE-2024-27443","CVE-2024-38112","CVE-2024-42009","CVE-2024-45195","CVE-2024-4671","CVE-2024-4947","CVE-2024-5274","CVE-2024-54085","CVE-2025-24016","CVE-2025-24201","CVE-2025-24993","CVE-2025-27038","CVE-2025-27363","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31200","CVE-2025-31201","CVE-2025-3248","CVE-2025-32756","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-49706","CVE-2025-5419","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"saas-googleworkspace","name":"saas:googleworkspace","channels":[{"channel":"API access without user login","analytics":["AN0957"],"data_components":["DC0002"]},{"channel":"Access via OAuth credentials with unusual scopes or from anomalous IPs","analytics":["AN1427"],"data_components":["DC0002"]},{"channel":"Accessed third-party credential management service","analytics":["AN1156"],"data_components":["DC0002"]},{"channel":"OAuth2 authorization grants / Admin role assignments","analytics":["AN1349"],"data_components":["DC0038"]},{"channel":"OAuthTokenGranted, APIRequest","analytics":["AN0528"],"data_components":["DC0007"]},{"channel":"access_token issued","analytics":["AN0957"],"data_components":["DC0007"]},{"channel":"login with reused session token and mismatched user agent or IP","analytics":["AN1406"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0007","DC0038"],"analytics":["AN0528","AN0957","AN1156","AN1349","AN1406","AN1427"],"techniques":["T1199","T1528","T1539","T1550","T1550.001","T1552"],"platforms":["SaaS"],"kev_cves":["CVE-2020-5902","CVE-2023-49103","CVE-2024-20439","CVE-2024-21887","CVE-2024-38475","CVE-2024-53704"]},{"slug":"saas-slack","name":"saas:slack","channels":[{"channel":"Exported file or accessed admin API","analytics":["AN1162"],"data_components":["DC0069"]},{"channel":"OAuth token use by unknown app client_id accessing private channels or files","analytics":["AN1427"],"data_components":["DC0038"]},{"channel":"chat.postMessage, files.upload, or discovery API calls involving token/credential regex","analytics":["AN0310"],"data_components":["DC0038"]},{"channel":"conversations.history, files.list, users.info, audit_logs","analytics":["AN1565"],"data_components":["DC0038"]},{"channel":"file_upload, message_send, message_click","analytics":["AN0150"],"data_components":["DC0038"]},{"channel":"xternal DM or workspace invite preceding credential or approval actions","analytics":["AN2034"],"data_components":["DC0038"]}],"data_components":["DC0038","DC0069"],"analytics":["AN0150","AN0310","AN1162","AN1427","AN1565","AN2034"],"techniques":["T1213","T1213.005","T1528","T1534","T1552.008","T1684"],"platforms":["SaaS"],"kev_cves":["CVE-2022-24086","CVE-2023-35078","CVE-2024-38475"]},{"slug":"internet-scan","name":"Internet Scan","channels":[{"channel":"None","analytics":["AN1952","AN1956","AN1957","AN1958","AN1961","AN1966","AN1968","AN1970","AN1971","AN1972","AN1976","AN1980","AN1982","AN1985","AN1986","AN1991","AN1996","AN2003","AN2006","AN2013","AN2014","AN2017","AN2019","AN2020","AN2025","AN2027","AN2028"],"data_components":["DC0104","DC0106"]}],"data_components":["DC0104","DC0106"],"analytics":["AN1952","AN1956","AN1957","AN1958","AN1961","AN1966","AN1968","AN1970","AN1971","AN1972","AN1976","AN1980","AN1982","AN1985","AN1986","AN1991","AN1996","AN2003","AN2006","AN2013","AN2014","AN2017","AN2019","AN2020","AN2025","AN2027","AN2028"],"techniques":["T1583","T1583.003","T1583.004","T1583.006","T1583.007","T1583.008","T1584","T1584.003","T1584.004","T1584.006","T1584.007","T1584.008","T1587","T1587.003","T1588","T1588.004","T1592","T1592.001","T1592.002","T1592.004","T1608","T1608.001","T1608.002","T1608.003","T1608.004","T1608.005","T1608.006"],"platforms":["PRE"],"kev_cves":["CVE-2013-0631","CVE-2017-12637","CVE-2019-0604","CVE-2021-44228","CVE-2023-33246","CVE-2023-39780","CVE-2024-20353","CVE-2024-37085","CVE-2024-54085","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-4632"]},{"slug":"networkdevice-flow","name":"networkdevice:Flow","channels":[{"channel":"Traffic from mirrored interface to mirror target IP","analytics":["AN1132"],"data_components":["DC0082"]}],"data_components":["DC0082"],"analytics":["AN1132"],"techniques":["T1020.001"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"esxi-esxupdate","name":"esxi:esxupdate","channels":[{"channel":"/var/log/esxupdate.log contains VIB installed with `--force` or `--no-sig-check` and non-standard acceptance levels","analytics":["AN1475"],"data_components":["DC0038"]},{"channel":"/var/log/esxupdate.log or /var/log/vmksummary.log","analytics":["AN1023"],"data_components":["DC0082"]}],"data_components":["DC0038","DC0082"],"analytics":["AN1023","AN1475"],"techniques":["T1090.003","T1505.006"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"esxi-vmkernel","name":"esxi:vmkernel","channels":[{"channel":"/var/log/vmkernel.log","analytics":["AN0116","AN0207","AN1023","AN1455","AN1629"],"data_components":["DC0061","DC0064","DC0078"]},{"channel":"DCUI shell start, BusyBox activity","analytics":["AN1083"],"data_components":["DC0064"]},{"channel":"DNS lookups resolving to domains with rapid changes in registration metadata","analytics":["AN1152"],"data_components":["DC0101"]},{"channel":"Datastore modification events","analytics":["AN1068"],"data_components":["DC0059"]},{"channel":"Disabling or modifying firewall rules","analytics":["AN0890"],"data_components":["DC0043"]},{"channel":"Exec","analytics":["AN0987"],"data_components":["DC0032"]},{"channel":"HTTPS POST connections to pastebin-like domains","analytics":["AN0790"],"data_components":["DC0085"]},{"channel":"HTTPS POST connections to webhook endpoints","analytics":["AN0439"],"data_components":["DC0085"]},{"channel":"HTTPS traffic to repository domains","analytics":["AN0898"],"data_components":["DC0078"]},{"channel":"Inspection of sockets showing encrypted sessions from non-baseline processes","analytics":["AN0762"],"data_components":["DC0085"]},{"channel":"Network activity","analytics":["AN0033"],"data_components":["DC0085"]},{"channel":"None","analytics":["AN0925","AN1232","AN1379"],"data_components":["DC0078","DC0082"]},{"channel":"Outbound traffic using encoded payloads post-login","analytics":["AN0305"],"data_components":["DC0085"]},{"channel":"Startup script and task execution logs","analytics":["AN0262"],"data_components":["DC0001"]},{"channel":"Storage access and file ops","analytics":["AN0654"],"data_components":["DC0059"]},{"channel":"Suspicious traffic filtered or redirected by VM networking stack","analytics":["AN1152"],"data_components":["DC0085"]},{"channel":"Unauthorized file modifications within datastore volumes via shell access or vCLI","analytics":["AN0665"],"data_components":["DC0061"]},{"channel":"Unexpected restarts of management agents or shell access","analytics":["AN1510"],"data_components":["DC0064"]},{"channel":"Upload of file to datastore","analytics":["AN0519"],"data_components":["DC0059"]},{"channel":"VM exit/entry anomalies, unexpected hypercalls, or kernel module loading","analytics":["AN0615"],"data_components":["DC0031"]},{"channel":"VMCI syslog entries","analytics":["AN1257"],"data_components":["DC0085"]},{"channel":"VMFS access logs","analytics":["AN0044"],"data_components":["DC0055"]},{"channel":"VMFS file creation","analytics":["AN0197"],"data_components":["DC0039"]},{"channel":"VMX startup messages without associated vCenter inventory records","analytics":["AN0912"],"data_components":["DC0028"]},{"channel":"boot","analytics":["AN0314"],"data_components":["DC0029"]},{"channel":"egress log analysis","analytics":["AN1392"],"data_components":["DC0078"]},{"channel":"egress logs","analytics":["AN1416"],"data_components":["DC0078"]},{"channel":"esxcli system account add","analytics":["AN1238"],"data_components":["DC0064"]},{"channel":"esxcli, vim-cmd invocation","analytics":["AN1537"],"data_components":["DC0064"]},{"channel":"file delete|datastore purge","analytics":["AN0415"],"data_components":["DC0098"]},{"channel":"file write","analytics":["AN0168"],"data_components":["DC0039"]},{"channel":"module load","analytics":["AN0987"],"data_components":["DC0016"]},{"channel":"network activity","analytics":["AN1192"],"data_components":["DC0082"]},{"channel":"network flows to external cloud services","analytics":["AN1574"],"data_components":["DC0078"]},{"channel":"network session initiation with external HTTPS services","analytics":["AN1515"],"data_components":["DC0082"]},{"channel":"network stack module logs","analytics":["AN0991"],"data_components":["DC0085"]},{"channel":"port 22 access","analytics":["AN1640"],"data_components":["DC0078"]},{"channel":"protocol egress","analytics":["AN0371"],"data_components":["DC0082"]},{"channel":"rename .vmdk to .*.locked|datastore write spike","analytics":["AN0605"],"data_components":["DC0061"]},{"channel":"snapshot create/write events","analytics":["AN0727"],"data_components":["DC0057"]},{"channel":"spawned shell or execution environment activity","analytics":["AN0807"],"data_components":["DC0032"]},{"channel":"unexpected module load","analytics":["AN0952"],"data_components":["DC0016"]},{"channel":"vim.fault.*, DCUI login, SSH shell","analytics":["AN0754"],"data_components":["DC0067"]}],"data_components":["DC0001","DC0016","DC0028","DC0029","DC0031","DC0032","DC0039","DC0043","DC0055","DC0057","DC0059","DC0061","DC0064","DC0067","DC0078","DC0082","DC0085","DC0098","DC0101"],"analytics":["AN0033","AN0044","AN0116","AN0168","AN0197","AN0207","AN0262","AN0305","AN0314","AN0371","AN0415","AN0439","AN0519","AN0605","AN0615","AN0654","AN0665","AN0727","AN0754","AN0762","AN0790","AN0807","AN0890","AN0898","AN0912","AN0925","AN0952","AN0987","AN0991","AN1023","AN1068","AN1083","AN1152","AN1192","AN1232","AN1238","AN1257","AN1379","AN1392","AN1416","AN1455","AN1510","AN1515","AN1537","AN1574","AN1629","AN1640"],"techniques":["T1001.001","T1001.002","T1008","T1021","T1021.004","T1027","T1036.005","T1037","T1041","T1048","T1048.001","T1048.002","T1053","T1053.003","T1059.004","T1059.012","T1070.006","T1070.009","T1074","T1074.001","T1074.002","T1082","T1090","T1090.001","T1090.002","T1090.003","T1095","T1102","T1105","T1132","T1136.001","T1485","T1486","T1491","T1505","T1554","T1564.006","T1567","T1567.001","T1567.002","T1567.003","T1567.004","T1570","T1573","T1611","T1665"],"platforms":["ESXi"],"kev_cves":["CVE-2009-3960","CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2010-2883","CVE-2011-0611","CVE-2012-0754","CVE-2012-1535","CVE-2013-0641","CVE-2014-6271","CVE-2014-7169","CVE-2015-5119","CVE-2015-8651","CVE-2016-0984","CVE-2016-10033","CVE-2016-1019","CVE-2016-4117","CVE-2017-11292","CVE-2017-6742","CVE-2018-15982","CVE-2018-4878","CVE-2018-7600","CVE-2019-0604","CVE-2019-0708","CVE-2019-11634","CVE-2019-1653","CVE-2019-18935","CVE-2019-3396","CVE-2020-1472","CVE-2020-8195","CVE-2020-8196","CVE-2021-22017","CVE-2021-22986","CVE-2021-26855","CVE-2021-34473","CVE-2021-35394","CVE-2021-36380","CVE-2021-39226","CVE-2021-40449","CVE-2021-40539","CVE-2021-42258","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-45046","CVE-2022-20699","CVE-2022-20700","CVE-2022-21999","CVE-2022-22947","CVE-2022-24086","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-30190","CVE-2022-41082","CVE-2022-41328","CVE-2022-47966","CVE-2023-0669","CVE-2023-1389","CVE-2023-20867","CVE-2023-22518","CVE-2023-26360","CVE-2023-27350","CVE-2023-27532","CVE-2023-28252","CVE-2023-2868","CVE-2023-29300","CVE-2023-34362","CVE-2023-3519","CVE-2023-36884","CVE-2023-38035","CVE-2023-38203","CVE-2023-38831","CVE-2023-39780","CVE-2023-43770","CVE-2023-44221","CVE-2023-46604","CVE-2023-48788","CVE-2023-5631","CVE-2023-7101","CVE-2024-11182","CVE-2024-20353","CVE-2024-20359","CVE-2024-23692","CVE-2024-24919","CVE-2024-27443","CVE-2024-4577","CVE-2024-4978","CVE-2024-55550","CVE-2024-55591","CVE-2025-21391","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226","CVE-2025-25181","CVE-2025-25257","CVE-2025-31200","CVE-2025-31201","CVE-2025-32433","CVE-2025-32756","CVE-2025-33053","CVE-2025-43200","CVE-2025-49706","CVE-2025-54309"]},{"slug":"wineventlog-microsoft-windows-windows-firewall-with-advanced-security-firewall","name":"WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall","channels":[{"channel":"EventCode=2004, 2005, 2006","analytics":["AN0842","AN1448"],"data_components":["DC0078"]},{"channel":"new rule allowing inbound or outbound connections for remote desktop software","analytics":["AN0714"],"data_components":["DC0051"]}],"data_components":["DC0051","DC0078"],"analytics":["AN0714","AN0842","AN1448"],"techniques":["T1205","T1205.001","T1219.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"google-admin-audit","name":"Google Admin Audit","channels":[{"channel":"users.list, groups.list","analytics":["AN1090"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN1090"],"techniques":["T1087.004"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"aws-cloudwatch","name":"AWS:CloudWatch","channels":[{"channel":"Elevated 5xx response rates in application logs or gateway layer","analytics":["AN1168"],"data_components":["DC0038"]},{"channel":"NetworkOut spike beyond baseline","analytics":["AN0972"],"data_components":["DC0018"]},{"channel":"Repeated crash pattern within container or instance logs","analytics":["AN0853"],"data_components":["DC0038"]},{"channel":"StatusCheckFailed or StatusCheckFailed_System for burstable instances (t2/t3)","analytics":["AN0587"],"data_components":["DC0018"]},{"channel":"Sudden spike in network output without a corresponding inbound request ratio","analytics":["AN1143"],"data_components":["DC0018"]},{"channel":"Sustained EC2 CPU usage above normal baseline","analytics":["AN0744"],"data_components":["DC0018"]},{"channel":"Sustained spike in CPU usage on EC2 instance with web service role","analytics":["AN0492"],"data_components":["DC0018"]},{"channel":"Unusual CPU burst or metric anomalies","analytics":["AN1493"],"data_components":["DC0018"]},{"channel":"unexpected IAM user or role assuming privileges for instance/snapshot operations","analytics":["AN0861"],"data_components":["DC0070"]}],"data_components":["DC0018","DC0038","DC0070"],"analytics":["AN0492","AN0587","AN0744","AN0853","AN0861","AN0972","AN1143","AN1168","AN1493"],"techniques":["T1496","T1496.001","T1498.001","T1498.002","T1499","T1499.002","T1499.003","T1499.004","T1578"],"platforms":["IaaS"],"kev_cves":["CVE-2015-3043","CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-5735","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2021-45382","CVE-2022-26258","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-20109","CVE-2023-22527","CVE-2023-32315","CVE-2023-38035","CVE-2023-44487","CVE-2023-47565","CVE-2023-49897","CVE-2023-6549","CVE-2024-23692","CVE-2024-45195","CVE-2024-54085","CVE-2025-27363","CVE-2025-42599","CVE-2025-4632"]},{"slug":"malware-repository","name":"Malware Repository","channels":[{"channel":"None","analytics":["AN1965","AN1977","AN1982","AN1984","AN1985","AN2004","AN2007"],"data_components":["DC0003","DC0011"]}],"data_components":["DC0003","DC0011"],"analytics":["AN1965","AN1977","AN1982","AN1984","AN1985","AN2004","AN2007"],"techniques":["T1587","T1587.001","T1587.002","T1588","T1588.001","T1588.002","T1588.003"],"platforms":["PRE"],"kev_cves":["CVE-2023-34048","CVE-2023-39780","CVE-2025-0411"]},{"slug":"etw-procthread","name":"ETW:ProcThread","channels":[{"channel":"api_call: CreateProcessWithTokenW, CreateProcessAsUserW","analytics":["AN1253"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN1253"],"techniques":["T1134.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"microsoft-graph-api-logs","name":"Microsoft Graph API Logs","channels":[{"channel":"users.list, directoryObjects.getByIds","analytics":["AN1089"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN1089"],"techniques":["T1087.004"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"wineventlog-microsoft-iis-configuration","name":"WinEventLog:Microsoft-IIS-Configuration","channels":[{"channel":"Module or ISAPI filter registration events","analytics":["AN0184"],"data_components":["DC0065"]}],"data_components":["DC0065"],"analytics":["AN0184"],"techniques":["T1505.004"],"platforms":["Windows"],"kev_cves":[]},{"slug":"esxis-vmkernel","name":"esxis:vmkernel","channels":[{"channel":"Datastore Access","analytics":["AN1074"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN1074"],"techniques":["T1005"],"platforms":["ESXi"],"kev_cves":["CVE-2013-0629","CVE-2017-11292","CVE-2017-5638","CVE-2018-0296","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-5591","CVE-2020-3452","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2021-26085","CVE-2021-26855","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-29256","CVE-2023-34362","CVE-2023-36884","CVE-2023-38831","CVE-2023-38950","CVE-2023-49103","CVE-2023-4966","CVE-2024-0769","CVE-2024-23692","CVE-2024-24919","CVE-2024-34102","CVE-2024-38475","CVE-2024-41713","CVE-2024-48248","CVE-2024-4879","CVE-2024-4978","CVE-2024-50302","CVE-2024-5217","CVE-2024-53150","CVE-2024-55550","CVE-2025-0111","CVE-2025-21418","CVE-2025-22226","CVE-2025-24991","CVE-2025-43200","CVE-2025-48927","CVE-2025-48928"]},{"slug":"windows-perfmon","name":"Windows:perfmon","channels":[{"channel":"High sustained CPU usage by a single process","analytics":["AN0741"],"data_components":["DC0018"]},{"channel":"Sudden spike in outbound throughput without corresponding inbound traffic","analytics":["AN1140"],"data_components":["DC0018"]},{"channel":"Sudden spikes in CPU/Memory usage linked to specific application processes","analytics":["AN1165"],"data_components":["DC0018"]},{"channel":"Sustained CPU/memory exhaustion by service process (e.g., w3wp.exe)","analytics":["AN0489"],"data_components":["DC0018"]}],"data_components":["DC0018"],"analytics":["AN0489","AN0741","AN1140","AN1165"],"techniques":["T1496","T1498.002","T1499.002","T1499.003"],"platforms":["Windows"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2021-45382","CVE-2022-26258","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-32315","CVE-2023-38035","CVE-2023-47565","CVE-2023-49897","CVE-2024-23692","CVE-2025-4632"]},{"slug":"azure-policy","name":"azure:policy","channels":[{"channel":"DisableAuditLogs or ConditionalAccess logging changes","analytics":["AN0802"],"data_components":["DC0069"]},{"channel":"DisableMfaPolicy or change to ConditionalAccess rules","analytics":["AN0892"],"data_components":["DC0010"]},{"channel":"UpdatePolicy","analytics":["AN0290"],"data_components":["DC0069"]}],"data_components":["DC0010","DC0069"],"analytics":["AN0290","AN0802","AN0892"],"techniques":["T1556","T1685.002"],"platforms":["Identity Provider"],"kev_cves":["CVE-2020-12812","CVE-2020-8193"]},{"slug":"m365-signinlogs","name":"m365:signinlogs","channels":[{"channel":"Sign-in from anomalous location or impossible travel condition","analytics":["AN0338"],"data_components":["DC0002"]},{"channel":"Token usage events with device/user mismatch","analytics":["AN0723"],"data_components":["DC0067"]},{"channel":"Unusual sign-in from service principal to user mailbox","analytics":["AN1107"],"data_components":["DC0002"]},{"channel":"UserLoggedIn","analytics":["AN1520","AN1565","AN1566"],"data_components":["DC0067"]},{"channel":"UserLogin","analytics":["AN1506"],"data_components":["DC0088"]},{"channel":"UserLogin: Discovery operations shortly after account logins from new geolocations","analytics":["AN1129"],"data_components":["DC0067"]},{"channel":"UserLoginSuccess","analytics":["AN0810"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0067","DC0088"],"analytics":["AN0338","AN0723","AN0810","AN1107","AN1129","AN1506","AN1520","AN1565","AN1566"],"techniques":["T1078.004","T1213.004","T1213.005","T1526","T1531","T1538","T1548.005","T1606"],"platforms":["Office Suite","SaaS"],"kev_cves":["CVE-2023-34362","CVE-2024-53704"]},{"slug":"domain-name","name":"Domain Name","channels":[{"channel":"None","analytics":["AN1995","AN2017","AN2023","AN2024","AN2027"],"data_components":["DC0096","DC0101","DC0103"]}],"data_components":["DC0096","DC0101","DC0103"],"analytics":["AN1995","AN2017","AN2023","AN2024","AN2027"],"techniques":["T1583","T1583.001","T1584","T1584.001","T1584.002"],"platforms":["PRE"],"kev_cves":[]},{"slug":"edr-detection","name":"EDR:detection","channels":[{"channel":"App reputation telemetry","analytics":["AN0872"],"data_components":["DC0059"]},{"channel":"ThreatDetected, QuarantineLog","analytics":["AN0541"],"data_components":["DC0038"]}],"data_components":["DC0038","DC0059"],"analytics":["AN0541","AN0872"],"techniques":["T1027.005","T1027.006"],"platforms":["Linux","Windows"],"kev_cves":[]},{"slug":"network-traffic","name":"Network Traffic","channels":[{"channel":"None","analytics":["AN0872","AN1946","AN1949","AN1953","AN1955","AN1962","AN1973","AN1983","AN1997","AN1999","AN2000","AN2002","AN2005","AN2008","AN2010"],"data_components":["DC0078","DC0085"]}],"data_components":["DC0078","DC0085"],"analytics":["AN0872","AN1946","AN1949","AN1953","AN1955","AN1962","AN1973","AN1983","AN1997","AN1999","AN2000","AN2002","AN2005","AN2008","AN2010"],"techniques":["T1027.006","T1585","T1585.001","T1586","T1586.001","T1589","T1589.002","T1595","T1595.001","T1595.002","T1595.003","T1598","T1598.001","T1598.002","T1598.003"],"platforms":["PRE","Windows"],"kev_cves":["CVE-2021-33739","CVE-2025-0282"]},{"slug":"esxi-vob","name":"esxi:vob","channels":[{"channel":"NFS/remote access logs","analytics":["AN0197"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0197"],"techniques":["T1074.002"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"nsm-connections","name":"NSM:Connections","channels":[{"channel":"Abnormal certificate chains or non-standard ports carrying TLS","analytics":["AN0763"],"data_components":["DC0085"]},{"channel":"Accepted password or publickey for user from remote IP","analytics":["AN0335"],"data_components":["DC0002"]},{"channel":"Accepted publickey for user from unusual IP or without tty","analytics":["AN0955"],"data_components":["DC0067"]},{"channel":"Failed password or accepted password for SSH users","analytics":["AN1005"],"data_components":["DC0038"]},{"channel":"Inbound on ports 5985/5986","analytics":["AN1313"],"data_components":["DC0078"]},{"channel":"Internal connection logging","analytics":["AN0205"],"data_components":["DC0078"]},{"channel":"Mismatch between recorded user logon and active sessions (e.g., wtmp/utmp entries without corresponding authentication in auth.log)","analytics":["AN0217"],"data_components":["DC0067"]},{"channel":"Missing new login event but session activity continues","analytics":["AN0710"],"data_components":["DC0067"]},{"channel":"New outbound connection from Safari/Chrome/Firefox/Word","analytics":["AN0180"],"data_components":["DC0082"]},{"channel":"Outbound Connection","analytics":["AN1229"],"data_components":["DC0078"]},{"channel":"Outbound connection after script or installer launch","analytics":["AN2036","AN2037"],"data_components":["DC0082"]},{"channel":"Outbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous ports","analytics":["AN0499"],"data_components":["DC0082"]},{"channel":"Pre-authentication keys generated or token signing anomalies","analytics":["AN0718"],"data_components":["DC0007"]},{"channel":"PushNotificationSent","analytics":["AN0449"],"data_components":["DC0038"]},{"channel":"Repeated failed authentication attempts or replay patterns","analytics":["AN0494"],"data_components":["DC0002"]},{"channel":"Successful login without expected MFA challenge","analytics":["AN0546"],"data_components":["DC0002"]},{"channel":"Successful sudo or ssh from unknown IPs","analytics":["AN1623"],"data_components":["DC0088"]},{"channel":"Symmetric encryption detected without TLS handshake sequence","analytics":["AN0404"],"data_components":["DC0085"]},{"channel":"TLS handshake + HTTP headers","analytics":["AN0564"],"data_components":["DC0085"]},{"channel":"Unusual POST requests to admin or upload endpoints","analytics":["AN1622"],"data_components":["DC0085"]},{"channel":"new connections from exploited lineage","analytics":["AN0799"],"data_components":["DC0078"]},{"channel":"simultaneous or anomalous logon sessions across multiple systems","analytics":["AN1250"],"data_components":["DC0067"]},{"channel":"sshd or PAM logins","analytics":["AN1544"],"data_components":["DC0002"]},{"channel":"web domain alerts","analytics":["AN0102"],"data_components":["DC0082"]}],"data_components":["DC0002","DC0007","DC0038","DC0067","DC0078","DC0082","DC0085","DC0088"],"analytics":["AN0102","AN0180","AN0205","AN0217","AN0335","AN0404","AN0449","AN0494","AN0499","AN0546","AN0564","AN0710","AN0718","AN0763","AN0799","AN0955","AN1005","AN1229","AN1250","AN1313","AN1544","AN1622","AN1623","AN2036","AN2037"],"techniques":["T1021.006","T1078","T1090","T1090.001","T1090.004","T1102.002","T1133","T1189","T1203","T1204.001","T1212","T1491.002","T1531","T1550","T1556.003","T1556.006","T1563","T1563.001","T1573","T1573.001","T1606","T1621","T1684"],"platforms":["Identity Provider","Linux","Network Devices","Windows","macOS"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-0767","CVE-2012-2034","CVE-2012-5054","CVE-2014-6271","CVE-2014-7169","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-5119","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2018-15961","CVE-2018-4939","CVE-2019-0708","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-1472","CVE-2020-25506","CVE-2020-3580","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-22017","CVE-2021-22894","CVE-2021-22899","CVE-2021-22986","CVE-2021-26855","CVE-2021-26857","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-36934","CVE-2021-37975","CVE-2021-39144","CVE-2021-40449","CVE-2021-40539","CVE-2021-41379","CVE-2021-42321","CVE-2021-44077","CVE-2022-1040","CVE-2022-20699","CVE-2022-20701","CVE-2022-20703","CVE-2022-21919","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-23131","CVE-2022-23748","CVE-2022-24521","CVE-2022-24682","CVE-2022-26500","CVE-2022-26904","CVE-2022-3038","CVE-2022-3075","CVE-2022-37969","CVE-2022-41073","CVE-2022-41082","CVE-2022-41125","CVE-2022-41128","CVE-2022-43769","CVE-2023-20109","CVE-2023-20118","CVE-2023-20269","CVE-2023-20273","CVE-2023-20867","CVE-2023-2136","CVE-2023-21608","CVE-2023-21674","CVE-2023-22515","CVE-2023-22952","CVE-2023-23397","CVE-2023-26369","CVE-2023-27524","CVE-2023-27532","CVE-2023-28229","CVE-2023-28252","CVE-2023-34048","CVE-2023-34362","CVE-2023-36844","CVE-2023-39780","CVE-2023-41179","CVE-2023-43770","CVE-2023-46805","CVE-2023-47565","CVE-2023-48365","CVE-2023-49897","CVE-2023-5217","CVE-2023-5631","CVE-2023-7024","CVE-2024-11120","CVE-2024-20359","CVE-2024-20399","CVE-2024-21893","CVE-2024-26169","CVE-2024-37085","CVE-2024-38112","CVE-2024-45195","CVE-2024-4671","CVE-2024-4947","CVE-2024-5274","CVE-2024-53704","CVE-2024-55591","CVE-2024-57968","CVE-2025-24016","CVE-2025-24201","CVE-2025-24993","CVE-2025-27038","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-3248","CVE-2025-32756","CVE-2025-3935","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-48927","CVE-2025-48928","CVE-2025-5419","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"saas-zoom","name":"saas:zoom","channels":[{"channel":"DisableMFA or RegisterNewFactor","analytics":["AN0548"],"data_components":["DC0010"]},{"channel":"New user created","analytics":["AN0901"],"data_components":["DC0014"]},{"channel":"Unexpected contact interaction preceding follow-on admin requests","analytics":["AN2034"],"data_components":["DC0038"]},{"channel":"Zoom Admin Dashboard accessed from unfamiliar IP/device","analytics":["AN0811"],"data_components":["DC0067"]},{"channel":"unusual web session tokens and automation patterns during login","analytics":["AN1156"],"data_components":["DC0038"]}],"data_components":["DC0010","DC0014","DC0038","DC0067"],"analytics":["AN0548","AN0811","AN0901","AN1156","AN2034"],"techniques":["T1136.003","T1538","T1552","T1556.006","T1684"],"platforms":["SaaS"],"kev_cves":["CVE-2020-5902","CVE-2023-49103","CVE-2024-20439","CVE-2024-21887"]},{"slug":"esxi-vpxd","name":"esxi:vpxd","channels":[{"channel":"/var/log/vmware/vpxd.log","analytics":["AN0593"],"data_components":["DC0002"]},{"channel":"ESXi process initiating asymmetric handshake with external host","analytics":["AN1499"],"data_components":["DC0038"]},{"channel":"ESXi processes relaying traffic via SSH or unexpected ports","analytics":["AN1486"],"data_components":["DC0078"]},{"channel":"ESXi service connections on unexpected ports","analytics":["AN0636"],"data_components":["DC0078"]},{"channel":"None","analytics":["AN1379"],"data_components":["DC0078"]},{"channel":"Symmetric crypto routines triggered for external session","analytics":["AN0403"],"data_components":["DC0038"]},{"channel":"TLS session established by ESXi service to unapproved endpoint","analytics":["AN0762"],"data_components":["DC0078"]},{"channel":"permission change operations on datastores or VMs","analytics":["AN0837"],"data_components":["DC0066"]},{"channel":"vCenter Management","analytics":["AN1617"],"data_components":["DC0064"]}],"data_components":["DC0002","DC0038","DC0064","DC0066","DC0078"],"analytics":["AN0403","AN0593","AN0636","AN0762","AN0837","AN1379","AN1486","AN1499","AN1617"],"techniques":["T1008","T1078.002","T1087","T1222","T1571","T1572","T1573","T1573.001","T1573.002"],"platforms":["ESXi"],"kev_cves":["CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2021-44515","CVE-2022-22960","CVE-2022-41082","CVE-2023-27532","CVE-2023-38035","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161"]},{"slug":"esxcli-network","name":"esxcli:network","channels":[{"channel":"Socket inspection showing RSA key exchange outside baseline endpoints","analytics":["AN1499"],"data_components":["DC0085"]},{"channel":"Socket sessions with randomized payloads inconsistent with TLS","analytics":["AN0403"],"data_components":["DC0085"]},{"channel":"listening sockets bound to non-standard ports","analytics":["AN0636"],"data_components":["DC0085"]},{"channel":"listening sockets bound with non-standard encapsulated protocols","analytics":["AN1486"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0403","AN0636","AN1486","AN1499"],"techniques":["T1571","T1572","T1573.001","T1573.002"],"platforms":["ESXi"],"kev_cves":["CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2023-38035"]},{"slug":"applicationlog-entraidportal","name":"ApplicationLog:EntraIDPortal","channels":[{"channel":"DeviceRegistration events","analytics":["AN0103"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0103"],"techniques":["T1098.005"],"platforms":["Identity Provider"],"kev_cves":[]},{"slug":"ebpf-tracepoints","name":"ebpf:tracepoints","channels":[{"channel":"Runtime memory overwrite of argv[] memory region","analytics":["AN0466"],"data_components":["DC0020"]}],"data_components":["DC0020"],"analytics":["AN0466"],"techniques":["T1036.011"],"platforms":["Linux"],"kev_cves":[]},{"slug":"linux-cli","name":"linux:cli","channels":[{"channel":"/home/*/.bash_history","analytics":["AN1592"],"data_components":["DC0064"]},{"channel":"Shell history logs","analytics":["AN1065"],"data_components":["DC0064"]},{"channel":"Terminal Command History","analytics":["AN1441"],"data_components":["DC0064"]},{"channel":"cleared or truncated .bash_history","analytics":["AN0521"],"data_components":["DC0038"]},{"channel":"command logging","analytics":["AN0904"],"data_components":["DC0064"]}],"data_components":["DC0038","DC0064"],"analytics":["AN0521","AN0904","AN1065","AN1441","AN1592"],"techniques":["T1027","T1049","T1056.002","T1070","T1114.003"],"platforms":["Linux"],"kev_cves":["CVE-2010-2883","CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2021-45382","CVE-2022-24086","CVE-2022-41128","CVE-2022-41328","CVE-2023-1389"]},{"slug":"linux-cron","name":"linux:cron","channels":[{"channel":"Scheduled execution of unknown or unusual script/binary","analytics":["AN1490"],"data_components":["DC0001"]},{"channel":"cron activity","analytics":["AN0325","AN0431","AN1119"],"data_components":["DC0005"]}],"data_components":["DC0001","DC0005"],"analytics":["AN0325","AN0431","AN1119","AN1490"],"techniques":["T1029","T1036.004","T1124","T1496.001"],"platforms":["Linux"],"kev_cves":[]},{"slug":"esxi-syslog","name":"esxi:syslog","channels":[{"channel":"/var/log/syslog.log","analytics":["AN1125"],"data_components":["DC0078"]},{"channel":"/var/log/vpxa.log task invocations tied to time configuration","analytics":["AN0433"],"data_components":["DC0005"]},{"channel":"DNS resolution events leading to outbound traffic on unexpected ports","analytics":["AN0731"],"data_components":["DC0078"]},{"channel":"Datastore file hidden or renamed unexpectedly","analytics":["AN1387"],"data_components":["DC0059"]},{"channel":"Frequent DNS queries with high entropy names or NXDOMAIN results","analytics":["AN1181"],"data_components":["DC0078"]},{"channel":"Frequent DNS resolution of same domain with rotating IPs","analytics":["AN1334"],"data_components":["DC0078"]},{"channel":"boot logs","analytics":["AN0660"],"data_components":["DC0064"]},{"channel":"esxcli network vswitch or DNS resolver configuration updates","analytics":["AN0112"],"data_components":["DC0078"]},{"channel":"guest OS outbound transfer logs","analytics":["AN0991"],"data_components":["DC0055"]}],"data_components":["DC0005","DC0055","DC0059","DC0064","DC0078"],"analytics":["AN0112","AN0433","AN0660","AN0731","AN0991","AN1125","AN1181","AN1334","AN1387"],"techniques":["T1037.004","T1041","T1071.004","T1124","T1564","T1568","T1568.001","T1568.002","T1568.003"],"platforms":["ESXi"],"kev_cves":["CVE-2018-4878","CVE-2019-0604","CVE-2019-18935","CVE-2023-1389","CVE-2023-2868","CVE-2023-38831","CVE-2023-5631","CVE-2024-27443","CVE-2024-4577","CVE-2024-55550","CVE-2025-32756","CVE-2025-33053"]},{"slug":"networkdevice-cli","name":"networkdevice:cli","channels":[{"channel":"CLI command","analytics":["AN0099"],"data_components":["DC0064"]},{"channel":"CLI command logs","analytics":["AN0427"],"data_components":["DC0064"]},{"channel":"Commands like 'no logging' or equivalents that disable session history","analytics":["AN1559"],"data_components":["DC0064"]},{"channel":"Execution of CLI commands altering crypto parameters (e.g., 'crypto key generate rsa modulus 512')","analytics":["AN0681"],"data_components":["DC0064"]},{"channel":"Execution of commands disabling crypto hardware acceleration (e.g., 'no crypto engine enable')","analytics":["AN1360"],"data_components":["DC0064"]},{"channel":"Execution of commands like 'show running-config', 'copy running-config', or 'export config'","analytics":["AN0647"],"data_components":["DC0064"]},{"channel":"Execution of commands such as 'copy tftp flash', 'boot system <image>', 'reload'","analytics":["AN1570"],"data_components":["DC0064"]},{"channel":"Execution of commands to load, copy, or replace system images (e.g., 'copy tftp flash', 'boot system')","analytics":["AN0482"],"data_components":["DC0064"]},{"channel":"Execution of privileged commands such as 'copy tftp flash', 'boot system', or 'debug memory'","analytics":["AN1293"],"data_components":["DC0064"]},{"channel":"Interface commands","analytics":["AN1233"],"data_components":["DC0064"]},{"channel":"None","analytics":["AN0563"],"data_components":["DC0064"]},{"channel":"Policy Update","analytics":["AN0208"],"data_components":["DC0064"]},{"channel":"command logging","analytics":["AN1073","AN1194"],"data_components":["DC0064"]},{"channel":"command logs","analytics":["AN0907"],"data_components":["DC0064"]},{"channel":"erase flash:, erase nvram:, format disk","analytics":["AN0885"],"data_components":["DC0064"]},{"channel":"erase flash:, erase startup-config, format disk","analytics":["AN0387"],"data_components":["DC0064"]},{"channel":"firewall disable commands or suspicious ACL modifications","analytics":["AN0410"],"data_components":["DC0051"]},{"channel":"format flash:, format disk, reformat commands","analytics":["AN0830"],"data_components":["DC0064"]},{"channel":"ip ssh pubkey-chain","analytics":["AN0354"],"data_components":["DC0064"]},{"channel":"shell command","analytics":["AN1432"],"data_components":["DC0064"]}],"data_components":["DC0051","DC0064"],"analytics":["AN0099","AN0208","AN0354","AN0387","AN0410","AN0427","AN0482","AN0563","AN0647","AN0681","AN0830","AN0885","AN0907","AN1073","AN1194","AN1233","AN1293","AN1360","AN1432","AN1559","AN1570"],"techniques":["T1005","T1006","T1016","T1048.003","T1049","T1057","T1059","T1090","T1090.001","T1098.004","T1561","T1561.001","T1561.002","T1600.001","T1600.002","T1601","T1601.001","T1601.002","T1602.002","T1686","T1690"],"platforms":["Network Devices"],"kev_cves":["CVE-2010-2883","CVE-2013-0629","CVE-2016-4437","CVE-2017-11292","CVE-2017-11882","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-0296","CVE-2018-11776","CVE-2018-6789","CVE-2018-7600","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-17558","CVE-2019-19781","CVE-2019-3396","CVE-2019-3398","CVE-2019-5591","CVE-2020-0787","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3452","CVE-2020-3580","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21972","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-26085","CVE-2021-26855","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-29256","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-35394","CVE-2021-35464","CVE-2021-40449","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-44168","CVE-2021-45046","CVE-2021-45382","CVE-2022-1040","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22947","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24521","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-40684","CVE-2022-41125","CVE-2022-41328","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2023-20109","CVE-2023-20118","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-22515","CVE-2023-22952","CVE-2023-2533","CVE-2023-26359","CVE-2023-27350","CVE-2023-28252","CVE-2023-2868","CVE-2023-33246","CVE-2023-33538","CVE-2023-34192","CVE-2023-34362","CVE-2023-35081","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-36884","CVE-2023-38035","CVE-2023-38831","CVE-2023-38950","CVE-2023-40044","CVE-2023-41179","CVE-2023-43770","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-4966","CVE-2023-7101","CVE-2024-0769","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-20359","CVE-2024-20399","CVE-2024-20953","CVE-2024-21413","CVE-2024-21887","CVE-2024-23692","CVE-2024-24919","CVE-2024-26169","CVE-2024-27198","CVE-2024-29059","CVE-2024-34102","CVE-2024-38475","CVE-2024-41710","CVE-2024-41713","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-48248","CVE-2024-4879","CVE-2024-4885","CVE-2024-4947","CVE-2024-4978","CVE-2024-50302","CVE-2024-50603","CVE-2024-5217","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2024-55550","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0111","CVE-2025-0994","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21418","CVE-2025-21590","CVE-2025-22226","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-24991","CVE-2025-27038","CVE-2025-30397","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-48927","CVE-2025-48928","CVE-2025-53770","CVE-2025-6543","CVE-2025-6554"]},{"slug":"dns-query","name":"dns:query","channels":[{"channel":"Excessive lookups for domains with suspicious WHOIS or short TTL values","analytics":["AN1148"],"data_components":["DC0101"]},{"channel":"Outbound resolution to hidden service domains (e.g., `.onion`)","analytics":["AN1020"],"data_components":["DC0078"]}],"data_components":["DC0078","DC0101"],"analytics":["AN1020","AN1148"],"techniques":["T1090.003","T1665"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-windows-defender-operational","name":"WinEventLog:Microsoft-Windows-Windows Defender/Operational","channels":[{"channel":"Suspicious file execution on removable media path","analytics":["AN0841"],"data_components":["DC0055"]},{"channel":"Unusual external domain access","analytics":["AN0922"],"data_components":["DC0085"]}],"data_components":["DC0055","DC0085"],"analytics":["AN0841","AN0922"],"techniques":["T1090.002","T1091"],"platforms":["Windows"],"kev_cves":["CVE-2024-50302","CVE-2024-53104","CVE-2024-53150","CVE-2024-53197","CVE-2025-24985","CVE-2025-24991"]},{"slug":"auditd-config-change","name":"auditd:CONFIG_CHANGE","channels":[{"channel":"/etc/fstab, /etc/systemd/*","analytics":["AN0934"],"data_components":["DC0040"]},{"channel":"/var/log/audit/audit.log","analytics":["AN0325"],"data_components":["DC0012"]},{"channel":"chmod or chown of hook files indicating privilege escalation or execution permission change","analytics":["AN0713"],"data_components":["DC0059"]},{"channel":"creation or modification of systemd services","analytics":["AN0200"],"data_components":["DC0060"]},{"channel":"delete: Modification of systemd unit files or config for security agents","analytics":["AN1370"],"data_components":["DC0041"]},{"channel":"udev rule reload or trigger command executed","analytics":["AN1056"],"data_components":["DC0064"]}],"data_components":["DC0012","DC0040","DC0041","DC0059","DC0060","DC0064"],"analytics":["AN0200","AN0325","AN0713","AN0934","AN1056","AN1370"],"techniques":["T1036.004","T1490","T1546.017","T1546.018","T1569.003","T1685"],"platforms":["Linux"],"kev_cves":["CVE-2023-36884","CVE-2025-21391"]},{"slug":"pf-logs","name":"PF:Logs","channels":[{"channel":"External traffic to remote access services","analytics":["AN1006"],"data_components":["DC0078"]},{"channel":"high out:in ratio or fixed-size periodic flows","analytics":["AN0929"],"data_components":["DC0078"]},{"channel":"outbound flows with bytes_out >> bytes_in","analytics":["AN0347"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0347","AN0929","AN1006"],"techniques":["T1132.001","T1132.002","T1133"],"platforms":["macOS"],"kev_cves":["CVE-2014-6271","CVE-2014-7169","CVE-2018-4939","CVE-2019-0708","CVE-2019-11510","CVE-2019-19781","CVE-2019-3396","CVE-2019-5591","CVE-2020-1472","CVE-2020-25506","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-22986","CVE-2021-26855","CVE-2021-26857","CVE-2022-20699","CVE-2023-20269","CVE-2023-27532","CVE-2023-39780","CVE-2023-48365","CVE-2024-11120","CVE-2024-45195","CVE-2025-32756"]},{"slug":"wineventlog-microsoft-windows-windows-camera-frame-server-operational","name":"WinEventLog:Microsoft-Windows-Windows Camera Frame Server/Operational","channels":[{"channel":"Process session start/stop events for camera pipeline by unexpected executables","analytics":["AN0568"],"data_components":["DC0034"]}],"data_components":["DC0034"],"analytics":["AN0568"],"techniques":["T1125"],"platforms":["Windows"],"kev_cves":[]},{"slug":"applicationlog-iis","name":"ApplicationLog:IIS","channels":[{"channel":"IIS W3C logs in C:\\inetpub\\logs\\LogFiles\\W3SVC* (spikes in 5xx, RCE/SQLi/path traversal/JNDI patterns)","analytics":["AN0219"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0219"],"techniques":["T1190"],"platforms":["Windows"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"fs-fsusage","name":"fs:fsusage","channels":[{"channel":"Detached process execution with no associated parent","analytics":["AN1224"],"data_components":["DC0021"]},{"channel":"Disk Activity Tracing","analytics":["AN0618"],"data_components":["DC0055"]},{"channel":"File Access Monitor","analytics":["AN0391"],"data_components":["DC0055"]},{"channel":"File IO","analytics":["AN0621"],"data_components":["DC0039"]},{"channel":"Filesystem Access Logging","analytics":["AN1322"],"data_components":["DC0061"]},{"channel":"Filesystem Call Monitoring","analytics":["AN1042"],"data_components":["DC0055"]},{"channel":"access to BPF devices or interface IOCTLs","analytics":["AN0877"],"data_components":["DC0064"]},{"channel":"binary execution of security_authtrampoline","analytics":["AN0977"],"data_components":["DC0032"]},{"channel":"create: Attachment file creation in ~/Library/Mail directories","analytics":["AN1011"],"data_components":["DC0039"]},{"channel":"disk activity on /Library/LaunchAgents or LaunchDaemons","analytics":["AN0260"],"data_components":["DC0039"]},{"channel":"file","analytics":["AN0313"],"data_components":["DC0055"]},{"channel":"file access to /usr/lib/cron/at and job execution path","analytics":["AN0945"],"data_components":["DC0061"]},{"channel":"file access to /usr/lib/cron/tabs/ and cron output files","analytics":["AN0806"],"data_components":["DC0061"]},{"channel":"file activity","analytics":["AN0659"],"data_components":["DC0039"]},{"channel":"file open for known browser cookie paths","analytics":["AN1404"],"data_components":["DC0055"]},{"channel":"file open/write","analytics":["AN0784","AN0921"],"data_components":["DC0039"]},{"channel":"file reads/writes from /Volumes/","analytics":["AN1412"],"data_components":["DC0055"]},{"channel":"file system activity monitor","analytics":["AN0344"],"data_components":["DC0064"]},{"channel":"file write","analytics":["AN1530"],"data_components":["DC0039"]},{"channel":"file write to launchd plist paths","analytics":["AN1577"],"data_components":["DC0061"]},{"channel":"filesystem activity","analytics":["AN0813"],"data_components":["DC0055"]},{"channel":"filesystem monitoring of exec/open","analytics":["AN0985"],"data_components":["DC0059"]},{"channel":"modification of existing LaunchAgents plist","analytics":["AN1208"],"data_components":["DC0061"]},{"channel":"open/read/mount operations","analytics":["AN1147"],"data_components":["DC0054"]},{"channel":"open/write/exec calls","analytics":["AN0249"],"data_components":["DC0039"]},{"channel":"read/write","analytics":["AN1072"],"data_components":["DC0055"]},{"channel":"truncate, unlink, write","analytics":["AN1439"],"data_components":["DC0061"]},{"channel":"unlink, fs_delete","analytics":["AN0522"],"data_components":["DC0040"]},{"channel":"unlink, write","analytics":["AN0394","AN0468"],"data_components":["DC0061"]},{"channel":"write or chmod to ~/Library/LaunchAgents/*.plist","analytics":["AN1208"],"data_components":["DC0039"]}],"data_components":["DC0021","DC0032","DC0039","DC0040","DC0054","DC0055","DC0059","DC0061","DC0064"],"analytics":["AN0249","AN0260","AN0313","AN0344","AN0391","AN0394","AN0468","AN0522","AN0618","AN0621","AN0659","AN0784","AN0806","AN0813","AN0877","AN0921","AN0945","AN0977","AN0985","AN1011","AN1042","AN1072","AN1147","AN1208","AN1224","AN1322","AN1404","AN1412","AN1439","AN1530","AN1577"],"techniques":["T1005","T1025","T1027.001","T1027.014","T1027.015","T1036.005","T1036.006","T1036.009","T1037","T1037.004","T1039","T1040","T1052","T1052.001","T1053","T1053.002","T1053.003","T1056.003","T1056.004","T1070","T1070.003","T1070.004","T1083","T1092","T1123","T1539","T1543","T1543.001","T1548","T1667","T1685.006"],"platforms":["macOS"],"kev_cves":["CVE-2013-0629","CVE-2017-11292","CVE-2017-12637","CVE-2017-5638","CVE-2018-0296","CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2019-1653","CVE-2019-19781","CVE-2019-5591","CVE-2020-3452","CVE-2020-5902","CVE-2020-8193","CVE-2020-8195","CVE-2020-8196","CVE-2021-26085","CVE-2021-26855","CVE-2021-27101","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-29256","CVE-2021-32030","CVE-2021-40539","CVE-2021-44077","CVE-2021-45382","CVE-2022-1040","CVE-2022-1388","CVE-2022-23131","CVE-2022-41128","CVE-2022-41328","CVE-2023-0386","CVE-2023-1389","CVE-2023-22952","CVE-2023-26360","CVE-2023-34362","CVE-2023-36884","CVE-2023-38831","CVE-2023-38950","CVE-2023-44221","CVE-2023-49103","CVE-2023-4966","CVE-2024-0769","CVE-2024-20353","CVE-2024-20359","CVE-2024-23692","CVE-2024-24919","CVE-2024-34102","CVE-2024-38475","CVE-2024-41713","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-4978","CVE-2024-50302","CVE-2024-5217","CVE-2024-53150","CVE-2024-53704","CVE-2024-55550","CVE-2025-0111","CVE-2025-21418","CVE-2025-22226","CVE-2025-24991","CVE-2025-2783","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-43200","CVE-2025-4428","CVE-2025-48927","CVE-2025-48928"]},{"slug":"wineventlog-wmi","name":"WinEventLog:WMI","channels":[{"channel":"Creation or modification of __EventFilter, __FilterToConsumerBinding, or CommandLineEventConsumer","analytics":["AN0024"],"data_components":["DC0008"]},{"channel":"EventCode=5857, 5858, 5860, 5861","analytics":["AN0236","AN1031","AN1177","AN1305","AN1551"],"data_components":["DC0008"]}],"data_components":["DC0008"],"analytics":["AN0024","AN0236","AN1031","AN1177","AN1305","AN1551"],"techniques":["T1047","T1222.001","T1480","T1480.001","T1546","T1546.003"],"platforms":["Windows"],"kev_cves":["CVE-2021-40539","CVE-2021-44077"]},{"slug":"saas-box","name":"saas:box","channels":[{"channel":"API calls exceeding baseline thresholds","analytics":["AN1514"],"data_components":["DC0085"]},{"channel":"User navigated to admin interface","analytics":["AN0811"],"data_components":["DC0038"]},{"channel":"collaboration.invite","analytics":["AN1582"],"data_components":["DC0027"]}],"data_components":["DC0027","DC0038","DC0085"],"analytics":["AN0811","AN1514","AN1582"],"techniques":["T1537","T1538","T1567"],"platforms":["SaaS"],"kev_cves":["CVE-2022-41082","CVE-2024-11182","CVE-2025-54309"]},{"slug":"networkdevice-firewall","name":"networkdevice:Firewall","channels":[{"channel":"Audit trail or CLI/API access indicating commands like no access-list, delete rule-set, clear config","analytics":["AN0855"],"data_components":["DC0064"]},{"channel":"Login from untrusted IP, or new admin account accessing firewall console/API","analytics":["AN0855"],"data_components":["DC0067"]},{"channel":"update_rule: Access control or NAT rule modified or disabled outside maintenance window","analytics":["AN0855"],"data_components":["DC0051"]}],"data_components":["DC0051","DC0064","DC0067"],"analytics":["AN0855"],"techniques":["T1686.002"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"alb-httplogs","name":"ALB:HTTPLogs","channels":[{"channel":"AWS ALB/ELB/GCP/Azure Application Gateway HTTP logs with unusual methods, long URIs, serialized payloads, 4xx/5xx bursts","analytics":["AN0223"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0223"],"techniques":["T1190"],"platforms":["IaaS"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"containerd-events","name":"containerd:Events","channels":[{"channel":"Docker or containerd image pulls and process executions","analytics":["AN0986"],"data_components":["DC0034"]},{"channel":"Image pull from untrusted registry (name NOT IN allowlist) or new digest never seen before","analytics":["AN0691"],"data_components":["DC0015"]},{"channel":"New container with suspicious image name or high resource usage","analytics":["AN0745"],"data_components":["DC0032"]},{"channel":"create","analytics":["AN1492"],"data_components":["DC0072"]},{"channel":"unusual process spawned from container image context","analytics":["AN1158"],"data_components":["DC0032"]}],"data_components":["DC0015","DC0032","DC0034","DC0072"],"analytics":["AN0691","AN0745","AN0986","AN1158","AN1492"],"techniques":["T1036.005","T1204.003","T1496","T1496.001","T1552"],"platforms":["Containers","Linux"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-5902","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-26360","CVE-2023-32315","CVE-2023-38035","CVE-2023-47565","CVE-2023-49103","CVE-2023-49897","CVE-2024-20439","CVE-2024-21887","CVE-2024-23692","CVE-2025-4632"]},{"slug":"m365-exchange","name":"m365:exchange","channels":[{"channel":"Admin Audit Logs, Transport Rules","analytics":["AN0740"],"data_components":["DC0038"]},{"channel":"Cmdlet - New-InboxRule","analytics":["AN1589"],"data_components":["DC0070"]},{"channel":"External sender message followed by user action involving links or attachments","analytics":["AN2033"],"data_components":["DC0038"]},{"channel":"FailedLogin","analytics":["AN1342"],"data_components":["DC0002"]},{"channel":"Get-RoleGroup, Get-DistributionGroup","analytics":["AN0696"],"data_components":["DC0064"]},{"channel":"Logon failure","analytics":["AN1269"],"data_components":["DC0002"]},{"channel":"MailDelivery: High-frequency delivery of messages or attachments to a single recipient","analytics":["AN1010"],"data_components":["DC0038"]},{"channel":"Mailbox access using SAML token without corresponding MFA event","analytics":["AN0422"],"data_components":["DC0007"]},{"channel":"MessageTrace logs","analytics":["AN1312"],"data_components":["DC0038"]},{"channel":"New-InboxRule: Automation that triggers abnormal forwarding or external link generation","analytics":["AN1054"],"data_components":["DC0038"]},{"channel":"Remove-InboxRule, Clear-Mailbox","analytics":["AN0525"],"data_components":["DC0012"]},{"channel":"Transport Rule Modification","analytics":["AN0737"],"data_components":["DC0038"]}],"data_components":["DC0002","DC0007","DC0012","DC0038","DC0064","DC0070"],"analytics":["AN0422","AN0525","AN0696","AN0737","AN0740","AN1010","AN1054","AN1269","AN1312","AN1342","AN1589","AN2033"],"techniques":["T1069.003","T1070","T1070.008","T1110.003","T1110.004","T1114","T1114.003","T1606.002","T1648","T1667","T1684"],"platforms":["Office Suite","Windows"],"kev_cves":["CVE-2020-0688","CVE-2021-45382","CVE-2022-41128","CVE-2023-1389","CVE-2024-27443","CVE-2024-42009"]},{"slug":"nsx-flowlogs","name":"NSX:FlowLogs","channels":[{"channel":"network_flow: bytes_out >> bytes_in to external","analytics":["AN0348"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0348"],"techniques":["T1132.001"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"esxi-auth","name":"esxi:auth","channels":[{"channel":"/var/log/auth.log","analytics":["AN1286"],"data_components":["DC0002"]},{"channel":"None","analytics":["AN1640"],"data_components":["DC0088"]},{"channel":"SSH session/login","analytics":["AN1537"],"data_components":["DC0002"]},{"channel":"Shell login or escalation","analytics":["AN1083"],"data_components":["DC0067"]},{"channel":"interactive shell or SSH access preceding storage enumeration","analytics":["AN0539"],"data_components":["DC0002"]},{"channel":"user session","analytics":["AN0098"],"data_components":["DC0034"]}],"data_components":["DC0002","DC0034","DC0067","DC0088"],"analytics":["AN0098","AN0539","AN1083","AN1286","AN1537","AN1640"],"techniques":["T1021.004","T1057","T1059.004","T1059.012","T1078.001","T1680"],"platforms":["ESXi"],"kev_cves":["CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2019-0708","CVE-2021-36380","CVE-2022-20699","CVE-2022-20700","CVE-2023-38831","CVE-2023-39780","CVE-2023-44221","CVE-2023-46604","CVE-2024-24919","CVE-2024-27443","CVE-2025-25257","CVE-2025-32433"]},{"slug":"fwupd-logs","name":"fwupd:logs","channels":[{"channel":"Firmware updates applied or failed","analytics":["AN1036"],"data_components":["DC0059"]}],"data_components":["DC0059"],"analytics":["AN1036"],"techniques":["T1195.003"],"platforms":["Linux"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-vss","name":"WinEventLog:Microsoft-Windows-VSS","channels":[{"channel":"Volume Shadow Copy Creation","analytics":["AN1611"],"data_components":["DC0097"]}],"data_components":["DC0097"],"analytics":["AN1611"],"techniques":["T1003.003"],"platforms":["Windows"],"kev_cves":["CVE-2021-40539","CVE-2021-44077","CVE-2024-24919"]},{"slug":"gcpauditlogs-login-googleapis-com","name":"GCPAuditLogs:login.googleapis.com","channels":[{"channel":"Failed sign-in events","analytics":["AN1526"],"data_components":["DC0002"]}],"data_components":["DC0002"],"analytics":["AN1526"],"techniques":["T1110.001"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"networkdevice-config","name":"networkdevice:config","channels":[{"channel":"Boot image path or firmware configuration variable modified outside of maintenance windows","analytics":["AN0276"],"data_components":["DC0004"]},{"channel":"Boot variable modified to point to non-standard or unsigned image","analytics":["AN0777"],"data_components":["DC0004"]},{"channel":"Configuration change events referencing encryption, TLS/SSL, or IPSec settings","analytics":["AN0961"],"data_components":["DC0061"]},{"channel":"Configuration changes referencing 'boot system tftp' or modification of startup-config pointing to external TFTP servers","analytics":["AN1603"],"data_components":["DC0064"]},{"channel":"Configuration changes referencing 'crypto', 'key length', 'cipher', or downgrade of encryption settings","analytics":["AN0681"],"data_components":["DC0061"]},{"channel":"Configuration changes referencing cryptographic hardware modules or disabling hardware acceleration","analytics":["AN1360"],"data_components":["DC0061"]},{"channel":"Configuration changes referencing older image versions or unexpected boot parameters","analytics":["AN1570"],"data_components":["DC0061"]},{"channel":"Configuration changes to boot variables, startup image paths, or checksum verification failures","analytics":["AN0482"],"data_components":["DC0061"]},{"channel":"Configuration changes to startup image paths, boot loader parameters, or debug flags","analytics":["AN1293"],"data_components":["DC0061"]},{"channel":"Configuration file modified or replaced on network device","analytics":["AN0826"],"data_components":["DC0061"]},{"channel":"Log entries indicating ROMMON image upgrade commands (boot system, upgrade rom-monitor)","analytics":["AN0497"],"data_components":["DC0004"]},{"channel":"NAT table modification (add/update/delete rule)","analytics":["AN0465"],"data_components":["DC0085"]},{"channel":"config-change: timezone or ntp server configuration change after a time query command","analytics":["AN0434"],"data_components":["DC0061"]},{"channel":"write: Startup configuration changes disabling security checks","analytics":["AN1374"],"data_components":["DC0041"]}],"data_components":["DC0004","DC0041","DC0061","DC0064","DC0085"],"analytics":["AN0276","AN0434","AN0465","AN0482","AN0497","AN0681","AN0777","AN0826","AN0961","AN1293","AN1360","AN1374","AN1570","AN1603"],"techniques":["T1124","T1542","T1542.001","T1542.004","T1542.005","T1557","T1599.001","T1600","T1600.001","T1600.002","T1601","T1601.001","T1601.002","T1685"],"platforms":["Network Devices"],"kev_cves":["CVE-2017-6742","CVE-2019-5591","CVE-2021-44168","CVE-2022-1040","CVE-2025-31200","CVE-2025-31201"]},{"slug":"docker-runtime","name":"docker:runtime","channels":[{"channel":"Termination of monitoring sidecar or security container","analytics":["AN0889"],"data_components":["DC0033"]},{"channel":"execution of cloud CLI tool (e.g., aws, az) inside container","analytics":["AN0958"],"data_components":["DC0038"]}],"data_components":["DC0033","DC0038"],"analytics":["AN0889","AN0958"],"techniques":["T1550"],"platforms":["Containers"],"kev_cves":[]},{"slug":"etw-microsoft-windows-win32k","name":"etw:Microsoft-Windows-Win32k","channels":[{"channel":"SendMessage, PostMessage, LVM_*","analytics":["AN0941"],"data_components":["DC0021"]},{"channel":"SetWindowLong, SetClassLong, NtUserMessageCall, SendNotifyMessage, PostMessage","analytics":["AN0608"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0608","AN0941"],"techniques":["T1055.011","T1055.015"],"platforms":["Windows"],"kev_cves":[]},{"slug":"gcp-workspaceaudit","name":"gcp:workspaceaudit","channels":[{"channel":"SendAs: Outbound messages with alias identities that differ from primary account","analytics":["AN0795"],"data_components":["DC0038"]},{"channel":"Token Generation via Domain Delegation","analytics":["AN1106"],"data_components":["DC0002"]},{"channel":"drive.activity logs","analytics":["AN1301"],"data_components":["DC0039"]}],"data_components":["DC0002","DC0038","DC0039"],"analytics":["AN0795","AN1106","AN1301"],"techniques":["T1080","T1548.005","T1684.001"],"platforms":["Identity Provider","SaaS"],"kev_cves":[]},{"slug":"gcp-iam","name":"gcp:iam","channels":[{"channel":"PrincipalEmail with serviceAccountTokenCreator impersonating new identity","analytics":["AN1106"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN1106"],"techniques":["T1548.005"],"platforms":["Identity Provider"],"kev_cves":[]},{"slug":"netfilter-iptables","name":"Netfilter/iptables","channels":[{"channel":"Forwarded packets log","analytics":["AN1021"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1021"],"techniques":["T1090.003"],"platforms":["Linux"],"kev_cves":[]},{"slug":"etw-microsoft-windows-dotnetruntime","name":"etw:Microsoft-Windows-DotNETRuntime","channels":[{"channel":"AssemblyLoad/ModuleLoad (Loader keyword) from Microsoft-Windows-DotNETRuntime","analytics":["AN0838"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0838"],"techniques":["T1620"],"platforms":["Windows"],"kev_cves":[]},{"slug":"etw-microsoft-antimalware-scan-interface","name":"etw:Microsoft-Antimalware-Scan-Interface","channels":[{"channel":"Amsi/Script content + API verdicts during in-memory staging","analytics":["AN0838"],"data_components":["DC0029"]}],"data_components":["DC0029"],"analytics":["AN0838"],"techniques":["T1620"],"platforms":["Windows"],"kev_cves":[]},{"slug":"auditd-file","name":"auditd:FILE","channels":[{"channel":"/home/*/.mozilla/firefox/*/logins.json OR /home/*/.config/google-chrome/*/Login Data","analytics":["AN0106"],"data_components":["DC0055"]},{"channel":"/proc/*/mem read attempt","analytics":["AN0157"],"data_components":["DC0055"]},{"channel":"Creation of hidden files (.*) in sensitive directories (/etc, /var, /usr/bin)","analytics":["AN1385"],"data_components":["DC0039"]},{"channel":"File creation with name starting with '.'","analytics":["AN0092"],"data_components":["DC0039"]},{"channel":"Modification of Display Manager configuration files (/etc/gdm3/*, /etc/lightdm/*)","analytics":["AN1002"],"data_components":["DC0061"]},{"channel":"Modification or deletion of /etc/audit/audit.rules or /etc/audit/audit.conf","analytics":["AN0171"],"data_components":["DC0061"]},{"channel":"create: Creation of .zip, .gz, .bz2 files in /tmp, /var/tmp, or /home directories","analytics":["AN0748"],"data_components":["DC0039"]},{"channel":"create: Creation of archive files in /tmp, /var/tmp, or user home directories","analytics":["AN0832"],"data_components":["DC0039"]},{"channel":"create: Creation of files ending in .tar, .gz, .bz2, .zip in /tmp or /var/tmp","analytics":["AN1459"],"data_components":["DC0039"]},{"channel":"create: Creation of files with anomalous headers and entropy levels in /tmp or user directories","analytics":["AN1214"],"data_components":["DC0039"]},{"channel":"create: New file created in system binaries or temp directories","analytics":["AN0517"],"data_components":["DC0039"]}],"data_components":["DC0039","DC0055","DC0061"],"analytics":["AN0092","AN0106","AN0157","AN0171","AN0517","AN0748","AN0832","AN1002","AN1214","AN1385","AN1459"],"techniques":["T1555.002","T1555.003","T1560","T1560.001","T1560.002","T1560.003","T1564","T1564.001","T1564.002","T1570","T1685.004"],"platforms":["Linux"],"kev_cves":["CVE-2021-40539","CVE-2021-44077","CVE-2024-4577"]},{"slug":"auditd-user-login","name":"auditd:USER_LOGIN","channels":[{"channel":"USER_AUTH","analytics":["AN1276"],"data_components":["DC0002"]},{"channel":"USER_LOGIN","analytics":["AN1138","AN1284"],"data_components":["DC0088"]}],"data_components":["DC0002","DC0088"],"analytics":["AN1138","AN1276","AN1284"],"techniques":["T1078.001","T1078.003","T1110"],"platforms":["Linux"],"kev_cves":["CVE-2020-0688","CVE-2020-1472","CVE-2021-44168"]},{"slug":"linux-auth","name":"linux:auth","channels":[{"channel":"User login event followed by unexpected process tree","analytics":["AN1096"],"data_components":["DC0067"]},{"channel":"sshd login","analytics":["AN1138"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0067"],"analytics":["AN1096","AN1138"],"techniques":["T1078.003","T1547.013"],"platforms":["Linux"],"kev_cves":["CVE-2021-44168"]},{"slug":"etw-microsoft-windows-kernel-process","name":"etw:Microsoft-Windows-Kernel-Process","channels":[{"channel":"APCQueueOperations","analytics":["AN0277"],"data_components":["DC0021"]},{"channel":"API Calls","analytics":["AN0822","AN2029"],"data_components":["DC0021"]},{"channel":"API calls","analytics":["AN1399"],"data_components":["DC0021"]},{"channel":"API tracing / stack tracing via ETW or telemetry-based EDR","analytics":["AN0250"],"data_components":["DC0021"]},{"channel":"CreateTransaction, CreateFileTransacted, RollbackTransaction, NtCreateProcessEx, NtCreateThreadEx","analytics":["AN1501"],"data_components":["DC0021"]},{"channel":"High-frequency or suspicious sequence of QueryPerformanceCounter/GetTickCount API calls from a non-standard process lineage","analytics":["AN0430"],"data_components":["DC0021"]},{"channel":"Memory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser process","analytics":["AN0498"],"data_components":["DC0020"]},{"channel":"NtQueryInformationProcess","analytics":["AN1045"],"data_components":["DC0021"]},{"channel":"NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread","analytics":["AN1076"],"data_components":["DC0021"]},{"channel":"WriteProcessMemory: WriteProcessMemory targeting regions containing KernelCallbackTable addresses","analytics":["AN1593"],"data_components":["DC0021"]},{"channel":"api_call: UpdateProcThreadAttribute (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS) and CreateProcess* with EXTENDED_STARTUPINFO_PRESENT / StartupInfoEx","analytics":["AN1351"],"data_components":["DC0021"]},{"channel":"process_start: EventHeader.ProcessId true parent vs reported PPID mismatch","analytics":["AN1351"],"data_components":["DC0034"]}],"data_components":["DC0020","DC0021","DC0034"],"analytics":["AN0250","AN0277","AN0430","AN0498","AN0822","AN1045","AN1076","AN1351","AN1399","AN1501","AN1593","AN2029"],"techniques":["T1027.007","T1036.012","T1055","T1055.003","T1055.004","T1055.012","T1055.013","T1124","T1134.004","T1189","T1574.013","T1622"],"platforms":["Windows"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-3113","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2020-29574","CVE-2022-42475","CVE-2023-0386","CVE-2023-34192","CVE-2023-43770","CVE-2023-6548","CVE-2023-7024","CVE-2024-38112","CVE-2024-40890","CVE-2024-40891","CVE-2024-4671","CVE-2024-4947","CVE-2024-50603","CVE-2024-5274","CVE-2024-56145","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-21418","CVE-2025-21480","CVE-2025-22224","CVE-2025-24201","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-31324","CVE-2025-5419","CVE-2025-6554","CVE-2025-6558"]},{"slug":"etw-microsoft-windows-wininet","name":"etw:Microsoft-Windows-WinINet","channels":[{"channel":"HTTPS Inspection","analytics":["AN0100"],"data_components":["DC0085"]},{"channel":"WinINet API telemetry","analytics":["AN1599"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0100","AN1599"],"techniques":["T1102.002","T1102.003"],"platforms":["Windows"],"kev_cves":[]},{"slug":"networkdevice-audit","name":"networkdevice:audit","channels":[{"channel":"SNMP configuration changes, such as enabling read/write access or modifying community strings","analytics":["AN1249"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN1249"],"techniques":["T1602.001"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"macos-keychain","name":"macos:keychain","channels":[{"channel":"Access to Keychain DB or system.keychain","analytics":["AN0650"],"data_components":["DC0055"]},{"channel":"~/Library/Keychains, /Library/Keychains","analytics":["AN0673"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN0650","AN0673"],"techniques":["T1003","T1649"],"platforms":["macOS"],"kev_cves":["CVE-2019-0604","CVE-2019-11634","CVE-2019-13608","CVE-2020-5902","CVE-2021-22893","CVE-2021-40539","CVE-2021-44077","CVE-2021-44515","CVE-2023-28252","CVE-2024-4577","CVE-2024-48248","CVE-2024-57727","CVE-2025-0282","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-32709","CVE-2025-32756"]},{"slug":"macos-auth","name":"macos:auth","channels":[{"channel":"~/.ssh/authorized_keys","analytics":["AN0351"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN0351"],"techniques":["T1098.004"],"platforms":["macOS"],"kev_cves":["CVE-2022-40684"]},{"slug":"containerd-runtime","name":"containerd:runtime","channels":[{"channel":"/var/log/containers/*.log","analytics":["AN0358"],"data_components":["DC0032"]},{"channel":"CRI CreateContainer/StartContainer with privileged=true OR added capabilities OR host* namespaces","analytics":["AN0693"],"data_components":["DC0077"]},{"channel":"container-level outbound traffic events","analytics":["AN1060"],"data_components":["DC0078"]},{"channel":"e.g., containerd, Docker events","analytics":["AN1422"],"data_components":["DC0091"]},{"channel":"file change monitoring within /etc/cron.*, /tmp, or mounted volumes","analytics":["AN0261"],"data_components":["DC0061"]}],"data_components":["DC0032","DC0061","DC0077","DC0078","DC0091"],"analytics":["AN0261","AN0358","AN0693","AN1060","AN1422"],"techniques":["T1036","T1046","T1053","T1068","T1610"],"platforms":["Containers"],"kev_cves":["CVE-2014-0546","CVE-2019-0211","CVE-2019-11634","CVE-2019-13608","CVE-2020-0069","CVE-2020-0787","CVE-2020-1472","CVE-2021-21973","CVE-2021-22900","CVE-2021-29256","CVE-2021-32030","CVE-2021-33739","CVE-2021-36934","CVE-2021-4034","CVE-2021-40449","CVE-2021-41379","CVE-2022-20708","CVE-2022-21919","CVE-2022-21999","CVE-2022-22047","CVE-2022-22718","CVE-2022-22948","CVE-2022-24521","CVE-2022-26500","CVE-2022-26501","CVE-2022-26904","CVE-2022-37969","CVE-2022-41033","CVE-2022-41073","CVE-2022-41125","CVE-2022-47966","CVE-2023-20118","CVE-2023-20273","CVE-2023-21674","CVE-2023-26360","CVE-2023-28229","CVE-2023-28252","CVE-2023-33538","CVE-2023-38035","CVE-2023-38831","CVE-2023-44221","CVE-2024-12686","CVE-2024-12987","CVE-2024-29059","CVE-2024-30051","CVE-2024-37085","CVE-2024-38080","CVE-2024-41710","CVE-2024-41713","CVE-2024-4577","CVE-2024-4885","CVE-2024-49035","CVE-2024-53104","CVE-2024-53197","CVE-2024-54085","CVE-2024-55591","CVE-2025-0111","CVE-2025-0282","CVE-2025-0994","CVE-2025-1976","CVE-2025-21333","CVE-2025-21334","CVE-2025-21335","CVE-2025-21391","CVE-2025-21418","CVE-2025-21590","CVE-2025-22225","CVE-2025-24085","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-30400","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-4632","CVE-2025-47812","CVE-2025-54309"]},{"slug":"esxi-vpxa","name":"esxi:vpxa","channels":[{"channel":"connection attempts and data transmission logs","analytics":["AN0991"],"data_components":["DC0078"]},{"channel":"user login from unexpected IP or non-admin user role","analytics":["AN0337"],"data_components":["DC0002"]},{"channel":"vim.SessionManager.login / vim.AccountManager.createUser","analytics":["AN0269"],"data_components":["DC0066"]}],"data_components":["DC0002","DC0066","DC0078"],"analytics":["AN0269","AN0337","AN0991"],"techniques":["T1041","T1098","T1531"],"platforms":["ESXi"],"kev_cves":["CVE-2012-0767","CVE-2018-4878","CVE-2019-0604","CVE-2019-18935","CVE-2021-32030","CVE-2023-1389","CVE-2023-2868","CVE-2023-34362","CVE-2023-38831","CVE-2023-5631","CVE-2024-27443","CVE-2024-4577","CVE-2024-55550","CVE-2025-32756","CVE-2025-33053"]},{"slug":"docker-api","name":"docker:api","channels":[{"channel":"docker logs access or container inspect commands from non-administrative users","analytics":["AN0571"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0571"],"techniques":["T1552.007"],"platforms":["Containers"],"kev_cves":[]},{"slug":"kubernetes-orchestrator","name":"kubernetes:orchestrator","channels":[{"channel":"Access to orchestrator logs containing credentials (Docker/Kubernetes logs)","analytics":["AN0571"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0571"],"techniques":["T1552.007"],"platforms":["Containers"],"kev_cves":[]},{"slug":"openbsm-audittrail","name":"OpenBSM:AuditTrail","channels":[{"channel":"BSM audit events for file permission, ownership, and attribute modifications with user context","analytics":["AN0999"],"data_components":["DC0059"]},{"channel":"open/openat of /dev/bpf*; ioctl BIOCSETF-like operations.","analytics":["AN0464"],"data_components":["DC0032"]}],"data_components":["DC0032","DC0059"],"analytics":["AN0464","AN0999"],"techniques":["T1205.002","T1222.002"],"platforms":["macOS"],"kev_cves":[]},{"slug":"applicationlogs-sql","name":"ApplicationLogs:SQL","channels":[{"channel":"Stored procedure creation or modification with shell invocation (e.g., system(), exec())","analytics":["AN0512"],"data_components":["DC0029"]}],"data_components":["DC0029"],"analytics":["AN0512"],"techniques":["T1505.001"],"platforms":["Linux"],"kev_cves":[]},{"slug":"persona","name":"Persona","channels":[{"channel":"None","analytics":["AN1983","AN2002","AN2005","AN2008"],"data_components":["DC0052"]}],"data_components":["DC0052"],"analytics":["AN1983","AN2002","AN2005","AN2008"],"techniques":["T1585","T1585.001","T1586","T1586.001"],"platforms":["PRE"],"kev_cves":[]},{"slug":"network-auth","name":"network:auth","channels":[{"channel":"repeated successful authentications with previously unknown accounts or anomalous password acceptance","analytics":["AN0758"],"data_components":["DC0002"]}],"data_components":["DC0002"],"analytics":["AN0758"],"techniques":["T1556.004"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"journald-application","name":"journald:Application","channels":[{"channel":"Segfault or crash log entry associated with specific application binary","analytics":["AN0851"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0851"],"techniques":["T1499.004"],"platforms":["Linux"],"kev_cves":["CVE-2015-3043","CVE-2025-27363"]},{"slug":"azure-ad","name":"azure:ad","channels":[{"channel":"SignInEvents","analytics":["AN1312"],"data_components":["DC0067"]}],"data_components":["DC0067"],"analytics":["AN1312"],"techniques":["T1114"],"platforms":["Office Suite"],"kev_cves":["CVE-2020-0688","CVE-2024-27443","CVE-2024-42009"]},{"slug":"containers-osquery","name":"containers:osquery","channels":[{"channel":"bandwidth-intensive command execution from within a container namespace","analytics":["AN0083"],"data_components":["DC0032"]}],"data_components":["DC0032"],"analytics":["AN0083"],"techniques":["T1496.002"],"platforms":["Containers"],"kev_cves":[]},{"slug":"docker-stats","name":"docker:stats","channels":[{"channel":"unusual network TX/RX byte deltas","analytics":["AN0083"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0083"],"techniques":["T1496.002"],"platforms":["Containers"],"kev_cves":[]},{"slug":"auditd-proctitle","name":"auditd:PROCTITLE","channels":[{"channel":"command-line execution patterns for system discovery utilities (uname, hostname, ifconfig, netstat, lsof, ps, mount)","analytics":["AN1552"],"data_components":["DC0064"]},{"channel":"proctitle contains chmod, chown, chgrp, setfacl, or attr with suspicious parameters (777, 755, +x, -R)","analytics":["AN0998"],"data_components":["DC0064"]},{"channel":"proctitle contains chmod, chown, setfacl, or attr commands with suspicious parameters","analytics":["AN0835"],"data_components":["DC0064"]},{"channel":"scripting loop invoking sleep/ping","analytics":["AN1049"],"data_components":["DC0029"]}],"data_components":["DC0029","DC0064"],"analytics":["AN0835","AN0998","AN1049","AN1552"],"techniques":["T1222","T1222.002","T1480","T1678"],"platforms":["Linux"],"kev_cves":["CVE-2022-22960"]},{"slug":"saas-auth","name":"saas:auth","channels":[{"channel":"API requests made with tokens not associated with expected user logins","analytics":["AN0722"],"data_components":["DC0007"]},{"channel":"Login, TokenGranted: Discovery actions tied to anomalous login sessions or tokens","analytics":["AN1130"],"data_components":["DC0067"]},{"channel":"LoginSuccess, APIKeyUse, AdminAction","analytics":["AN0020"],"data_components":["DC0067"]},{"channel":"Refresh token issuance or refresh token usage from new IPs or user agents","analytics":["AN0501"],"data_components":["DC0013"]},{"channel":"signin_failed","analytics":["AN1343"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0007","DC0013","DC0067"],"analytics":["AN0020","AN0501","AN0722","AN1130","AN1343"],"techniques":["T1021.007","T1110.003","T1189","T1526","T1606"],"platforms":["Identity Provider","SaaS"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2012-2034","CVE-2012-5054","CVE-2014-8439","CVE-2015-0310","CVE-2015-0313","CVE-2015-3043","CVE-2015-8651","CVE-2016-1019","CVE-2016-7855","CVE-2023-43770","CVE-2023-7024","CVE-2024-38112","CVE-2024-4671","CVE-2024-4947","CVE-2024-5274","CVE-2025-24201","CVE-2025-5419","CVE-2025-6554","CVE-2025-6558"]},{"slug":"fs-fileevents","name":"fs:fileevents","channels":[{"channel":"/Library/LaunchDaemons/*.plist, ~/Library/LaunchAgents/*.plist","analytics":["AN0326"],"data_components":["DC0005"]},{"channel":"/var/log/install.log","analytics":["AN0090","AN0357"],"data_components":["DC0059","DC0061"]},{"channel":"/var/log/quarantine.log","analytics":["AN0013"],"data_components":["DC0061"]},{"channel":"File system access events with kFSEventStreamEventFlagItemRemoved, kFSEventStreamEventFlagItemRenamed flags for environmental artifact collection (/System/Library, /usr/sbin, plist files)","analytics":["AN1553"],"data_components":["DC0055"]},{"channel":"creat","analytics":["AN0253"],"data_components":["DC0039"]},{"channel":"create/write/rename in user-writable paths","analytics":["AN1316"],"data_components":["DC0039"]}],"data_components":["DC0005","DC0039","DC0055","DC0059","DC0061"],"analytics":["AN0013","AN0090","AN0253","AN0326","AN0357","AN1316","AN1553"],"techniques":["T1036","T1036.001","T1036.003","T1036.004","T1176","T1204","T1480"],"platforms":["Linux","macOS"],"kev_cves":["CVE-2022-26500","CVE-2022-26501","CVE-2023-38831","CVE-2025-24993"]},{"slug":"m365-dirsync","name":"m365:dirsync","channels":[{"channel":"Replication cookie changes involving Configuration partition with new server/nTDSDSA objects.","analytics":["AN0770"],"data_components":["DC0066"]}],"data_components":["DC0066"],"analytics":["AN0770"],"techniques":["T1207"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-confluence","name":"saas:confluence","channels":[{"channel":"REST API access from non-browser agents","analytics":["AN1019"],"data_components":["DC0085"]},{"channel":"access.content","analytics":["AN1019","AN1162"],"data_components":["DC0038"]},{"channel":"logon","analytics":["AN1019"],"data_components":["DC0067"]}],"data_components":["DC0038","DC0067","DC0085"],"analytics":["AN1019","AN1162"],"techniques":["T1213","T1213.001"],"platforms":["SaaS"],"kev_cves":["CVE-2022-24086","CVE-2023-35078"]},{"slug":"docker-daemon","name":"docker:daemon","channels":[{"channel":"ExecCreate + usermod or useradd","analytics":["AN1080"],"data_components":["DC0014"]},{"channel":"container create/start with privileged flag or host volume mount","analytics":["AN0612"],"data_components":["DC0072"]},{"channel":"container file operations","analytics":["AN0523"],"data_components":["DC0040"]},{"channel":"container_create,container_start","analytics":["AN0693"],"data_components":["DC0038"]},{"channel":"docker build or POST /build API request","analytics":["AN1261"],"data_components":["DC0015"]},{"channel":"docker build or docker commit commands followed by docker push to internal registry","analytics":["AN0946"],"data_components":["DC0015"]},{"channel":"docker exec or docker run with unexpected command/entrypoint","analytics":["AN0177"],"data_components":["DC0064"]},{"channel":"docker ps, docker inspect, or docker images commands","analytics":["AN1352"],"data_components":["DC0091"]}],"data_components":["DC0014","DC0015","DC0038","DC0040","DC0064","DC0072","DC0091"],"analytics":["AN0177","AN0523","AN0612","AN0693","AN0946","AN1080","AN1261","AN1352"],"techniques":["T1036.010","T1070","T1525","T1609","T1610","T1611","T1612","T1613"],"platforms":["Containers"],"kev_cves":["CVE-2021-45382","CVE-2022-41128","CVE-2023-1389","CVE-2025-22224","CVE-2025-22225","CVE-2025-22226"]},{"slug":"networkdevice-firmware","name":"networkdevice:firmware","channels":[{"channel":"Firmware update initiated or bootloader tampering detected","analytics":["AN0477"],"data_components":["DC0004"]},{"channel":"Unexpected firmware image upload events via TFTP/FTP/SCP","analytics":["AN0777"],"data_components":["DC0046"]}],"data_components":["DC0004","DC0046"],"analytics":["AN0477","AN0777"],"techniques":["T1495","T1542"],"platforms":["Network Devices"],"kev_cves":["CVE-2024-54085","CVE-2025-21480"]},{"slug":"wineventlog-microsoft-windows-codeintegrity-operational","name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channels":[{"channel":"Code integrity violations in boot-start drivers or firmware","analytics":["AN1035"],"data_components":["DC0059"]},{"channel":"CodeIntegrity reports 'Invalid image hash' or 'Unsigned image' for new/updated binaries","analytics":["AN1480"],"data_components":["DC0059"]},{"channel":"CodeIntegrity/WDAC events indicating unsigned/invalid DLL loads","analytics":["AN0052"],"data_components":["DC0034"]},{"channel":"Invalid/Unsigned image when developer tool launches newly installed binaries","analytics":["AN0021"],"data_components":["DC0059"]},{"channel":"Unsigned or invalid image for newly installed/updated binaries","analytics":["AN0862"],"data_components":["DC0059"]},{"channel":"Unsigned or untrusted modules loaded during JamPlus.exe runtime","analytics":["AN1610"],"data_components":["DC0034"]},{"channel":"Unsigned/invalid signature modules or images loaded by msbuild.exe or its children","analytics":["AN1535"],"data_components":["DC0034"]}],"data_components":["DC0034","DC0059"],"analytics":["AN0021","AN0052","AN0862","AN1035","AN1480","AN1535","AN1610"],"techniques":["T1127.001","T1127.003","T1129","T1195","T1195.001","T1195.002","T1195.003"],"platforms":["Windows"],"kev_cves":["CVE-2021-44529","CVE-2024-49035","CVE-2024-4978"]},{"slug":"docker-events","name":"docker:events","channels":[{"channel":"Container exited with non-zero code repeatedly in short period","analytics":["AN0588"],"data_components":["DC0038"]},{"channel":"Docker/Kubernetes audit of exec/attach (kubectl exec) or unexpected child processes inside container","analytics":["AN0222"],"data_components":["DC0032"]},{"channel":"container exec rm|container stop --force","analytics":["AN0416"],"data_components":["DC0064"]},{"channel":"created,started: new container from untrusted registry or unexpected entrypoint","analytics":["AN1317"],"data_components":["DC0072"]},{"channel":"docker run with restart=always or modifying init","analytics":["AN1578"],"data_components":["DC0072"]},{"channel":"docker.events.json","analytics":["AN0358"],"data_components":["DC0028"]},{"channel":"exec_create: docker exec events targeting running containers from non-CI sources","analytics":["AN0233"],"data_components":["DC0077"]},{"channel":"remote API calls to /containers/create or /containers/{id}/start","analytics":["AN0693"],"data_components":["DC0085"]},{"channel":"start","analytics":["AN1317"],"data_components":["DC0077"]}],"data_components":["DC0028","DC0032","DC0038","DC0064","DC0072","DC0077","DC0085"],"analytics":["AN0222","AN0233","AN0358","AN0416","AN0588","AN0693","AN1317","AN1578"],"techniques":["T1036","T1059.013","T1190","T1204","T1485","T1499","T1543","T1610"],"platforms":["Containers"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5735","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0386","CVE-2023-0669","CVE-2023-20109","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38831","CVE-2023-38950","CVE-2023-42793","CVE-2023-44221","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-6549","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-54085","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-21391","CVE-2025-22457","CVE-2025-23006","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-33053","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"m365-purview","name":"m365:purview","channels":[{"channel":"MailItemsAccessed & Exchange Audit","analytics":["AN0131"],"data_components":["DC0038"]},{"channel":"MailItemsAccessed, Search-Mailbox events","analytics":["AN0132"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0131","AN0132"],"techniques":["T1114.002"],"platforms":["Office Suite","Windows"],"kev_cves":["CVE-2012-0767"]},{"slug":"saas-finance","name":"saas:finance","channels":[{"channel":"Transaction/Transfer: Unusual or large transactions initiated outside business hours or by unusual accounts","analytics":["AN1364"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN1364"],"techniques":["T1657"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"azure-activity","name":"azure:activity","channels":[{"channel":"Azure CLI Operation: Microsoft.Graph/users/read","analytics":["AN1088"],"data_components":["DC0013"]},{"channel":"CollectGuestLogs: Unexpected collection of guest logs by Azure VM Agent outside normal maintenance windows","analytics":["AN0708"],"data_components":["DC0055"]},{"channel":"MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE","analytics":["AN0234"],"data_components":["DC0081"]},{"channel":"MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE","analytics":["AN1242"],"data_components":["DC0076"]},{"channel":"Microsoft.Compute/virtualMachines/runCommand/action: Abnormal initiation of Azure RunCommand jobs or PowerShell/Bash payloads","analytics":["AN1502"],"data_components":["DC0029"]},{"channel":"Microsoft.Compute/virtualMachines/write: imageReference publisher NOT IN allowlist OR plan is new/unknown","analytics":["AN0692"],"data_components":["DC0076"]},{"channel":"Update conditionalAccessPolicy","analytics":["AN0088"],"data_components":["DC0066"]},{"channel":"networkInsightsLogs","analytics":["AN0908"],"data_components":["DC0085"]},{"channel":"operationName: Write, Access Review, RoleAssignment","analytics":["AN0215"],"data_components":["DC0069"]}],"data_components":["DC0013","DC0029","DC0055","DC0066","DC0069","DC0076","DC0081","DC0085"],"analytics":["AN0088","AN0215","AN0234","AN0692","AN0708","AN0908","AN1088","AN1242","AN1502"],"techniques":["T1049","T1059.009","T1087.004","T1204.003","T1556.009","T1578.002","T1578.003","T1651","T1654"],"platforms":["IaaS","Identity Provider","Windows"],"kev_cves":["CVE-2022-41328"]},{"slug":"ids-tlsinspection","name":"IDS:TLSInspection","channels":[{"channel":"Malformed certs, incomplete asymmetric handshakes, or invalid CAs","analytics":["AN1500"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1500"],"techniques":["T1573.002"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"esxi-cron","name":"esxi:cron","channels":[{"channel":"execution of scheduled job","analytics":["AN0807"],"data_components":["DC0001"]},{"channel":"manual edits to /etc/rc.local.d/local.sh or cron.d","analytics":["AN0262"],"data_components":["DC0061"]},{"channel":"process or cron activity","analytics":["AN0640"],"data_components":["DC0032"]}],"data_components":["DC0001","DC0032","DC0061"],"analytics":["AN0262","AN0640","AN0807"],"techniques":["T1053","T1053.003","T1104"],"platforms":["ESXi"],"kev_cves":["CVE-2023-38831","CVE-2024-4577"]},{"slug":"m365-defender","name":"m365:defender","channels":[{"channel":"Activity Log: Command Invocation","analytics":["AN1087"],"data_components":["DC0064"]},{"channel":"NetworkConnection: high out:in ratio, periodic beacons, protocol mismatch","analytics":["AN0927"],"data_components":["DC0078"]},{"channel":"OfficeTelemetry or DLP","analytics":["AN1302"],"data_components":["DC0061"]},{"channel":"ScriptBlockLogging + AMSI","analytics":["AN0733"],"data_components":["DC0029"]}],"data_components":["DC0029","DC0061","DC0064","DC0078"],"analytics":["AN0733","AN0927","AN1087","AN1302"],"techniques":["T1059.007","T1080","T1087.004","T1132.002"],"platforms":["Identity Provider","Office Suite","Windows"],"kev_cves":["CVE-2013-3346","CVE-2015-5119","CVE-2018-4990","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-30554","CVE-2021-37975","CVE-2022-22963","CVE-2022-24682","CVE-2023-22515","CVE-2023-26360","CVE-2023-5631","CVE-2025-34028"]},{"slug":"nsm-firewall","name":"NSM:Firewall","channels":[{"channel":"Anomalous TCP SYN or ACK spikes from specific source or interface","analytics":["AN1014"],"data_components":["DC0085"]},{"channel":"High rate of inbound TCP SYN or ACK packets with missing 3-way handshake completion","analytics":["AN1012"],"data_components":["DC0085"]},{"channel":"ICMP/UDP protocol anomaly","analytics":["AN1258"],"data_components":["DC0085"]},{"channel":"Outbound Connections","analytics":["AN0161"],"data_components":["DC0082"]},{"channel":"Outbound connections to 139/445 to multiple destinations","analytics":["AN0515"],"data_components":["DC0078"]},{"channel":"Outbound encrypted traffic","analytics":["AN1024"],"data_components":["DC0085"]},{"channel":"Policy Change / Rule Update","analytics":["AN1233"],"data_components":["DC0051"]},{"channel":"TLS/HTTP inspection","analytics":["AN0567"],"data_components":["DC0085"]},{"channel":"inbound connection to port 5900","analytics":["AN0506"],"data_components":["DC0078"]},{"channel":"pf firewall logs","analytics":["AN1231"],"data_components":["DC0078"]},{"channel":"proxy or TLS inspection logs","analytics":["AN0285"],"data_components":["DC0082"]},{"channel":"rule_modification: New or modified firewall rules related to wireless interfaces","analytics":["AN1479"],"data_components":["DC0051"]}],"data_components":["DC0051","DC0078","DC0082","DC0085"],"analytics":["AN0161","AN0285","AN0506","AN0515","AN0567","AN1012","AN1014","AN1024","AN1231","AN1233","AN1258","AN1479"],"techniques":["T1021.005","T1056","T1090","T1090.003","T1090.004","T1095","T1102.001","T1135","T1499.001","T1669"],"platforms":["ESXi","Network Devices","Windows","macOS"],"kev_cves":["CVE-2019-3396","CVE-2020-8195","CVE-2020-8196","CVE-2021-22986","CVE-2021-26855","CVE-2024-42009"]},{"slug":"firewall-audit-logs","name":"Firewall Audit Logs","channels":[{"channel":"Config Change","analytics":["AN0208"],"data_components":["DC0051"]},{"channel":"Outbound NAT Rule Changes","analytics":["AN0926"],"data_components":["DC0051"]}],"data_components":["DC0051"],"analytics":["AN0208","AN0926"],"techniques":["T1090.001","T1090.002"],"platforms":["Network Devices"],"kev_cves":["CVE-2021-22017"]},{"slug":"edr-memory","name":"EDR:memory","channels":[{"channel":"MemoryWriteToExecutable","analytics":["AN1289"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN1289"],"techniques":["T1055.005"],"platforms":["Windows"],"kev_cves":[]},{"slug":"vpcflowlogs-all","name":"VPCFlowLogs:All","channels":[{"channel":"High volume internal traffic with low entropy indicating looped or malicious DoS script","analytics":["AN0587"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0587"],"techniques":["T1499"],"platforms":["IaaS"],"kev_cves":["CVE-2020-5735","CVE-2021-35394","CVE-2023-20109","CVE-2023-44487","CVE-2023-6549","CVE-2024-54085","CVE-2025-42599"]},{"slug":"edr-file","name":"EDR:file","channels":[{"channel":"File Metadata Analysis (PE overlays, entropy)","analytics":["AN0599"],"data_components":["DC0059"]},{"channel":"File Metadata Inspection (Low String Entropy, Missing PDB)","analytics":["AN0055"],"data_components":["DC0059"]},{"channel":"SetFileTime","analytics":["AN1626"],"data_components":["DC0021"]}],"data_components":["DC0021","DC0059"],"analytics":["AN0055","AN0599","AN1626"],"techniques":["T1027.008","T1027.009","T1070.006"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-salesforce","name":"saas:salesforce","channels":[{"channel":"API login using access_token without login history","analytics":["AN0528"],"data_components":["DC0002"]},{"channel":"ConnectedApp OAuth policy change / Login as user","analytics":["AN1349"],"data_components":["DC0088"]},{"channel":"DataExport, RestAPI, Login, ReportExport","analytics":["AN1520"],"data_components":["DC0038"]},{"channel":"GET /services/data/vXX.X/groups","analytics":["AN0697"],"data_components":["DC0099"]},{"channel":"Login","analytics":["AN0811"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0038","DC0088","DC0099"],"analytics":["AN0528","AN0697","AN0811","AN1349","AN1520"],"techniques":["T1069.003","T1199","T1213.004","T1538","T1550.001"],"platforms":["SaaS"],"kev_cves":["CVE-2024-53704"]},{"slug":"applicationlog-mailserver","name":"ApplicationLog:MailServer","channels":[{"channel":"Unexpected additions of sieve rules or filtering directives","analytics":["AN0553"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0553"],"techniques":["T1564.008"],"platforms":["Linux"],"kev_cves":[]},{"slug":"saas-api","name":"saas:api","channels":[{"channel":"Webhook registrations or repeated POST activity","analytics":["AN0440"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0440"],"techniques":["T1567.004"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"linuxsyslog","name":"linuxsyslog","channels":[{"channel":"nslcd or winbind logs","analytics":["AN0364"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0364"],"techniques":["T1087.002"],"platforms":["Linux"],"kev_cves":["CVE-2020-1472","CVE-2021-40539","CVE-2021-44077","CVE-2023-32315","CVE-2023-3519"]},{"slug":"fs-launchdaemons","name":"fs:launchdaemons","channels":[{"channel":"file_create","analytics":["AN1126"],"data_components":["DC0039"]},{"channel":"file_modify","analytics":["AN1126"],"data_components":["DC0061"]}],"data_components":["DC0039","DC0061"],"analytics":["AN1126"],"techniques":["T1543.004"],"platforms":["macOS"],"kev_cves":[]},{"slug":"kubernetes-events","name":"kubernetes:events","channels":[{"channel":"CrashLoopBackOff, OOMKilled, container restart count exceeds threshold","analytics":["AN0588"],"data_components":["DC0018"]},{"channel":"container start/stop activity via Docker, containerd, or CRI-O","analytics":["AN0582"],"data_components":["DC0072"]},{"channel":"start: ContainerStarted or Pulling image → Started container","analytics":["AN0691"],"data_components":["DC0077"]}],"data_components":["DC0018","DC0072","DC0077"],"analytics":["AN0582","AN0588","AN0691"],"techniques":["T1053.007","T1204.003","T1499"],"platforms":["Containers","Linux"],"kev_cves":["CVE-2020-5735","CVE-2021-35394","CVE-2023-20109","CVE-2023-44487","CVE-2023-6549","CVE-2024-54085","CVE-2025-42599"]},{"slug":"edr-hunting","name":"EDR:hunting","channels":[{"channel":"Advanced Hunting: DeviceProcessEvents + DeviceNetworkEvents","analytics":["AN0172"],"data_components":["DC0085"]},{"channel":"Behavioral rule for registry enumeration under credential-related paths","analytics":["AN0694"],"data_components":["DC0050"]}],"data_components":["DC0050","DC0085"],"analytics":["AN0172","AN0694"],"techniques":["T1059.006","T1552.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-collaboration","name":"saas:collaboration","channels":[{"channel":"MessagePosted: Suspicious links or attachment delivery via collaboration tools (Slack, Teams, Zoom)","analytics":["AN0193"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0193"],"techniques":["T1566"],"platforms":["SaaS"],"kev_cves":["CVE-2021-40449","CVE-2022-34713","CVE-2022-41128","CVE-2023-36884","CVE-2024-11182","CVE-2025-24054"]},{"slug":"m365-sharepoint","name":"m365:sharepoint","channels":[{"channel":"AnonymousLinkCreated, FileDownloaded","analytics":["AN1330"],"data_components":["DC0025"]},{"channel":"Enumerate ACLs/role bindings","analytics":["AN0696"],"data_components":["DC0105"]},{"channel":"File access with forged or anomalous SAML claims","analytics":["AN0422"],"data_components":["DC0067"]},{"channel":"Multiple file download operations on a site by a privileged account in a short time window","analytics":["AN1380"],"data_components":["DC0070"]}],"data_components":["DC0025","DC0067","DC0070","DC0105"],"analytics":["AN0422","AN0696","AN1330","AN1380"],"techniques":["T1069.003","T1213.002","T1530","T1606.002"],"platforms":["Office Suite","Windows"],"kev_cves":["CVE-2023-22952","CVE-2024-49035"]},{"slug":"wineventlog-iis","name":"WinEventLog:iis","channels":[{"channel":"IIS Logs","analytics":["AN1321"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1321"],"techniques":["T1056.003"],"platforms":["Windows"],"kev_cves":[]},{"slug":"macos-mdm","name":"macos:MDM","channels":[{"channel":"profiles -P|getaccountpolicies","analytics":["AN0457"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN0457"],"techniques":["T1201"],"platforms":["macOS"],"kev_cves":[]},{"slug":"journald-systemd","name":"journald:systemd","channels":[{"channel":"Repeated service restart attempts or unit failures","analytics":["AN0585"],"data_components":["DC0038"]},{"channel":"udisks2 or udevd logs","analytics":["AN1411"],"data_components":["DC0042"]}],"data_components":["DC0038","DC0042"],"analytics":["AN0585","AN1411"],"techniques":["T1025","T1499"],"platforms":["Linux"],"kev_cves":["CVE-2020-5735","CVE-2021-35394","CVE-2023-20109","CVE-2023-44487","CVE-2023-6549","CVE-2024-54085","CVE-2025-42599"]},{"slug":"esxi-vobd","name":"esxi:vobd","channels":[{"channel":"/var/log/vobd.log","analytics":["AN0175"],"data_components":["DC0032"]},{"channel":"Network Events","analytics":["AN0161"],"data_components":["DC0078"]},{"channel":"shell session start","analytics":["AN1431"],"data_components":["DC0064"]}],"data_components":["DC0032","DC0064","DC0078"],"analytics":["AN0161","AN0175","AN1431"],"techniques":["T1059","T1059.006","T1102.001"],"platforms":["ESXi"],"kev_cves":["CVE-2010-2883","CVE-2016-4437","CVE-2017-11882","CVE-2017-5638","CVE-2017-6742","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-6789","CVE-2018-7600","CVE-2019-11510","CVE-2019-11580","CVE-2019-11634","CVE-2019-13608","CVE-2019-17558","CVE-2019-19781","CVE-2019-3398","CVE-2020-0787","CVE-2020-15505","CVE-2020-17530","CVE-2020-25506","CVE-2020-29557","CVE-2020-29574","CVE-2020-3580","CVE-2020-5902","CVE-2020-8515","CVE-2021-1497","CVE-2021-1498","CVE-2021-20035","CVE-2021-21972","CVE-2021-22005","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22894","CVE-2021-22900","CVE-2021-22986","CVE-2021-26084","CVE-2021-27101","CVE-2021-27102","CVE-2021-27104","CVE-2021-31166","CVE-2021-3129","CVE-2021-35394","CVE-2021-35464","CVE-2021-41773","CVE-2021-42013","CVE-2021-42237","CVE-2021-42258","CVE-2021-42321","CVE-2021-45046","CVE-2021-45382","CVE-2022-1040","CVE-2022-21971","CVE-2022-21999","CVE-2022-22047","CVE-2022-22947","CVE-2022-22965","CVE-2022-23131","CVE-2022-23748","CVE-2022-24521","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-29303","CVE-2022-34713","CVE-2022-35405","CVE-2022-35914","CVE-2022-36804","CVE-2022-37969","CVE-2022-39197","CVE-2022-41125","CVE-2022-42948","CVE-2022-43769","CVE-2022-43939","CVE-2023-20109","CVE-2023-20118","CVE-2023-20273","CVE-2023-20867","CVE-2023-20887","CVE-2023-22515","CVE-2023-22952","CVE-2023-2533","CVE-2023-26359","CVE-2023-27350","CVE-2023-28252","CVE-2023-2868","CVE-2023-33246","CVE-2023-33538","CVE-2023-34192","CVE-2023-34362","CVE-2023-35081","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-40044","CVE-2023-41179","CVE-2023-43770","CVE-2023-48365","CVE-2023-48788","CVE-2023-7101","CVE-2024-11182","CVE-2024-12686","CVE-2024-12987","CVE-2024-20359","CVE-2024-20399","CVE-2024-20953","CVE-2024-21413","CVE-2024-21887","CVE-2024-26169","CVE-2024-27198","CVE-2024-29059","CVE-2024-34102","CVE-2024-38475","CVE-2024-41710","CVE-2024-45195","CVE-2024-4577","CVE-2024-4671","CVE-2024-4761","CVE-2024-4879","CVE-2024-4885","CVE-2024-4947","CVE-2024-50603","CVE-2024-5217","CVE-2024-53104","CVE-2024-53197","CVE-2024-56145","CVE-2024-57727","CVE-2024-57968","CVE-2024-58136","CVE-2024-6047","CVE-2025-0994","CVE-2025-1976","CVE-2025-20281","CVE-2025-20337","CVE-2025-21590","CVE-2025-22457","CVE-2025-23006","CVE-2025-24016","CVE-2025-24085","CVE-2025-24201","CVE-2025-24985","CVE-2025-27038","CVE-2025-30397","CVE-2025-30406","CVE-2025-31161","CVE-2025-31200","CVE-2025-31201","CVE-2025-31324","CVE-2025-32433","CVE-2025-3248","CVE-2025-32701","CVE-2025-32706","CVE-2025-32709","CVE-2025-32756","CVE-2025-33053","CVE-2025-35939","CVE-2025-3928","CVE-2025-3935","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-4632","CVE-2025-47812","CVE-2025-53770","CVE-2025-6543","CVE-2025-6554"]},{"slug":"macos-syslog","name":"macos:syslog","channels":[{"channel":"/var/log/system.log","analytics":["AN0734"],"data_components":["DC0064"]},{"channel":"DYLD_INSERT_LIBRARIES anomalies","analytics":["AN1401"],"data_components":["DC0016"]},{"channel":"system.log","analytics":["AN0173","AN0210"],"data_components":["DC0064"]},{"channel":"system.log, asl.log","analytics":["AN1082"],"data_components":["DC0029"]}],"data_components":["DC0016","DC0029","DC0064"],"analytics":["AN0173","AN0210","AN0734","AN1082","AN1401"],"techniques":["T1055","T1059.004","T1059.005","T1059.006","T1059.007"],"platforms":["macOS"],"kev_cves":["CVE-2013-3346","CVE-2014-6271","CVE-2014-7169","CVE-2015-5119","CVE-2016-10033","CVE-2018-4990","CVE-2019-0708","CVE-2020-29574","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-30554","CVE-2021-36380","CVE-2021-37975","CVE-2022-20699","CVE-2022-20700","CVE-2022-22963","CVE-2022-24682","CVE-2023-22515","CVE-2023-26360","CVE-2023-34192","CVE-2023-38831","CVE-2023-39780","CVE-2023-44221","CVE-2023-46604","CVE-2023-5631","CVE-2023-6548","CVE-2024-24919","CVE-2024-27443","CVE-2024-40890","CVE-2024-40891","CVE-2024-50603","CVE-2024-56145","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-21418","CVE-2025-21480","CVE-2025-22224","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-31324","CVE-2025-34028"]},{"slug":"saas-snowflake","name":"saas:Snowflake","channels":[{"channel":"QUERY: Large or repeated SELECT * queries to sensitive tables","analytics":["AN0680"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0680"],"techniques":["T1213.006"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"linus-syslog","name":"linus:syslog","channels":[{"channel":"None","analytics":["AN0272"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0272"],"techniques":["T1010"],"platforms":["Linux"],"kev_cves":[]},{"slug":"etw-microsoft-windows-ndis-packetcapture","name":"etw:Microsoft-Windows-NDIS-PacketCapture","channels":[{"channel":"TLS Handshake/Network Flow","analytics":["AN0158"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0158"],"techniques":["T1102.001"],"platforms":["Windows"],"kev_cves":[]},{"slug":"certificate","name":"Certificate","channels":[{"channel":"None","analytics":["AN1980","AN1982"],"data_components":["DC0093"]}],"data_components":["DC0093"],"analytics":["AN1980","AN1982"],"techniques":["T1588","T1588.004"],"platforms":["PRE"],"kev_cves":["CVE-2023-39780"]},{"slug":"application-log","name":"Application Log","channels":[{"channel":"None","analytics":["AN1942","AN1953","AN1955","AN1997","AN2010","AN2018"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN1942","AN1953","AN1955","AN1997","AN2010","AN2018"],"techniques":["T1594","T1598","T1598.001","T1598.002","T1598.003","T1598.004"],"platforms":["PRE"],"kev_cves":["CVE-2021-33739"]},{"slug":"wineventlog-taskscheduler","name":"WinEventLog:TaskScheduler","channels":[{"channel":"EventCode=106","analytics":["AN0113","AN0311","AN0430"],"data_components":["DC0001"]},{"channel":"Task registration/execution shortly after a time discovery event","analytics":["AN0430"],"data_components":["DC0005"]}],"data_components":["DC0001","DC0005"],"analytics":["AN0113","AN0311","AN0430"],"techniques":["T1037","T1070.009","T1124"],"platforms":["Windows"],"kev_cves":["CVE-2022-41328","CVE-2024-20353","CVE-2024-20359"]},{"slug":"snmp-access","name":"snmp:access","channels":[{"channel":"GETBULK/GETNEXT requests for OIDs associated with configuration parameters","analytics":["AN0647"],"data_components":["DC0082"]}],"data_components":["DC0082"],"analytics":["AN0647"],"techniques":["T1602.002"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"m365-mailboxaudit","name":"m365:mailboxaudit","channels":[{"channel":"Outlook rule creation or custom form deployment","analytics":["AN1117"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN1117"],"techniques":["T1137"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"azure-vpcflow","name":"azure:vpcflow","channels":[{"channel":"HTTP requests to 169.254.169.254 or Azure Metadata endpoints","analytics":["AN0122"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0122"],"techniques":["T1614"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"wineventlog-codeintegrity","name":"WinEventLog:CodeIntegrity","channels":[{"channel":"EventCode=3033","analytics":["AN1222"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN1222"],"techniques":["T1553.003"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-application","name":"saas:application","channels":[{"channel":"High-frequency invocation of SMS-related API endpoints from publicly accessible OTP or verification forms (e.g., Twilio: SendMessage, Cognito: AdminCreateUser) with irregular destination patterns.","analytics":["AN0443"],"data_components":["DC0038"]},{"channel":"High-volume API calls or traffic via messaging or webhook service","analytics":["AN0746"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0443","AN0746"],"techniques":["T1496","T1496.003"],"platforms":["SaaS"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-32315","CVE-2023-38035","CVE-2023-47565","CVE-2023-49897","CVE-2024-23692","CVE-2025-4632"]},{"slug":"cloudtrail-signin","name":"CloudTrail:Signin","channels":[{"channel":"SAML login without corresponding IdP authentication log","analytics":["AN0419"],"data_components":["DC0067"]}],"data_components":["DC0067"],"analytics":["AN0419"],"techniques":["T1606.002"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"wineventlog-adfs","name":"WinEventLog:ADFS","channels":[{"channel":"Token issuance events showing anomalous claims or issuers","analytics":["AN0420"],"data_components":["DC0006"]}],"data_components":["DC0006"],"analytics":["AN0420"],"techniques":["T1606.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"cloudtrail-getcalleridentity","name":"CloudTrail:GetCallerIdentity","channels":[{"channel":"GetCallerIdentity","analytics":["AN0690"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN0690"],"techniques":["T1535"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"ebpf-syscalls","name":"ebpf:syscalls","channels":[{"channel":"Process within container accesses link-local address 169.254.169.254","analytics":["AN0001"],"data_components":["DC0085"]},{"channel":"Unexpected container volume unmount + file deletion","analytics":["AN0523"],"data_components":["DC0059"]},{"channel":"container_file_activity","analytics":["AN0600"],"data_components":["DC0055"]},{"channel":"execve","analytics":["AN1060"],"data_components":["DC0032"]},{"channel":"file_write","analytics":["AN0358"],"data_components":["DC0061"]},{"channel":"open/read on secret mount paths","analytics":["AN0859"],"data_components":["DC0055"]},{"channel":"process execution or network connect from just-created container PID namespace","analytics":["AN0693"],"data_components":["DC0032"]},{"channel":"socket connect","analytics":["AN1060"],"data_components":["DC0082"]},{"channel":"useradd or /etc/passwd modified inside container","analytics":["AN1239"],"data_components":["DC0064"]}],"data_components":["DC0032","DC0055","DC0059","DC0061","DC0064","DC0082","DC0085"],"analytics":["AN0001","AN0358","AN0523","AN0600","AN0693","AN0859","AN1060","AN1239"],"techniques":["T1027.009","T1036","T1046","T1070","T1136.001","T1552.001","T1552.005","T1610"],"platforms":["Containers","IaaS","Linux"],"kev_cves":["CVE-2019-11510","CVE-2019-11634","CVE-2019-13608","CVE-2021-21973","CVE-2021-45382","CVE-2022-21999","CVE-2022-26138","CVE-2022-26500","CVE-2022-26501","CVE-2022-41128","CVE-2022-47966","CVE-2023-1389","CVE-2023-26360","CVE-2023-38035","CVE-2024-57727","CVE-2025-0282","CVE-2025-32756"]},{"slug":"gcp-audit","name":"gcp:audit","channels":[{"channel":"API Key Created, OAuth Client Registered","analytics":["AN1471"],"data_components":["DC0010"]},{"channel":"Directory API Access","analytics":["AN1618"],"data_components":["DC0013"]},{"channel":"Directory API Access: users.list or groups.list","analytics":["AN0642"],"data_components":["DC0013"]},{"channel":"None","analytics":["AN0017"],"data_components":["DC0064"]},{"channel":"Write operations to storage","analytics":["AN0043"],"data_components":["DC0055"]},{"channel":"admin.googleapis.com","analytics":["AN1504"],"data_components":["DC0067"]},{"channel":"compute.instances.setMetadata","analytics":["AN0352"],"data_components":["DC0061"]},{"channel":"drive.activity","analytics":["AN1505"],"data_components":["DC0002"]},{"channel":"google.iam.credentials.generateAccessToken / serviceAccountTokenCreator","analytics":["AN1348"],"data_components":["DC0088"]},{"channel":"iam.serviceAccounts.keys.create, os-login.sshPublicKeys.add","analytics":["AN1470"],"data_components":["DC0010"]},{"channel":"login.event","analytics":["AN1506"],"data_components":["DC0002"]}],"data_components":["DC0002","DC0010","DC0013","DC0055","DC0061","DC0064","DC0067","DC0088"],"analytics":["AN0017","AN0043","AN0352","AN0642","AN1348","AN1470","AN1471","AN1504","AN1505","AN1506","AN1618"],"techniques":["T1021.007","T1074","T1078.004","T1087","T1087.003","T1098.001","T1098.004","T1199"],"platforms":["IaaS","Office Suite","SaaS"],"kev_cves":["CVE-2021-44515","CVE-2022-40684","CVE-2022-41082","CVE-2023-27532","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-53704"]},{"slug":"gatekeeper-quarantine-database","name":"gatekeeper/quarantine database","channels":[{"channel":"LaunchServices quarantine","analytics":["AN0874"],"data_components":["DC0059"]}],"data_components":["DC0059"],"analytics":["AN0874"],"techniques":["T1027.006"],"platforms":["macOS"],"kev_cves":[]},{"slug":"edr-scriptblock","name":"EDR:scriptblock","channels":[{"channel":"Process Tree + Script Block Logging","analytics":["AN0578"],"data_components":["DC0029"]}],"data_components":["DC0029"],"analytics":["AN0578"],"techniques":["T1059.003"],"platforms":["Windows"],"kev_cves":["CVE-2021-22899","CVE-2021-40449","CVE-2023-27532","CVE-2023-42793","CVE-2025-49704","CVE-2025-49706"]},{"slug":"linux-procfs","name":"linux:procfs","channels":[{"channel":"/proc/[pid]/maps, /proc/[pid]/mem","analytics":["AN1400"],"data_components":["DC0020"]},{"channel":"Sustained high /proc/[pid]/stat usage","analytics":["AN0742"],"data_components":["DC0018"]}],"data_components":["DC0018","DC0020"],"analytics":["AN0742","AN1400"],"techniques":["T1055","T1496"],"platforms":["Linux"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-29574","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-32315","CVE-2023-34192","CVE-2023-38035","CVE-2023-47565","CVE-2023-49897","CVE-2023-6548","CVE-2024-23692","CVE-2024-40890","CVE-2024-40891","CVE-2024-50603","CVE-2024-56145","CVE-2024-58136","CVE-2024-6047","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-21418","CVE-2025-21480","CVE-2025-22224","CVE-2025-24993","CVE-2025-25181","CVE-2025-25257","CVE-2025-31324","CVE-2025-4632"]},{"slug":"m365-messagetrace","name":"m365:messagetrace","channels":[{"channel":"AuthenticationDetails=fail OR SPF=fail OR DKIM=fail OR DMARC=fail","analytics":["AN1202"],"data_components":["DC0038"]},{"channel":"Inbound email matches crafted rule trigger pattern tied to persistence logic","analytics":["AN0264"],"data_components":["DC0064"]},{"channel":"Inbound email triggering Outlook to auto-access folder tied to malicious Home Page","analytics":["AN0503"],"data_components":["DC0064"]},{"channel":"Inbound email triggers execution of mailbox-stored custom form","analytics":["AN0086"],"data_components":["DC0064"]},{"channel":"X-MS-Exchange-Organization-AutoForwarded","analytics":["AN1591"],"data_components":["DC0038"]}],"data_components":["DC0038","DC0064"],"analytics":["AN0086","AN0264","AN0503","AN1202","AN1591"],"techniques":["T1114.003","T1137.003","T1137.004","T1137.005","T1684.002"],"platforms":["Office Suite","Windows"],"kev_cves":[]},{"slug":"wineventlog-dhcp","name":"wineventlog:dhcp","channels":[{"channel":"DHCP Lease Granted","analytics":["AN0185"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0185"],"techniques":["T1200"],"platforms":["Windows"],"kev_cves":[]},{"slug":"iptables-log","name":"iptables:LOG","channels":[{"channel":"OUTBOUND","analytics":["AN0638","AN1600"],"data_components":["DC0078"]},{"channel":"TCP connections","analytics":["AN0166"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0166","AN0638","AN1600"],"techniques":["T1102.003","T1104","T1105"],"platforms":["Linux"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2011-0611","CVE-2012-0754","CVE-2012-1535","CVE-2013-0641","CVE-2015-5119","CVE-2015-8651","CVE-2016-0984","CVE-2016-1019","CVE-2016-4117","CVE-2017-11292","CVE-2018-15982","CVE-2021-35394","CVE-2021-44515","CVE-2022-30190","CVE-2023-20867","CVE-2023-22518","CVE-2023-26360","CVE-2023-27350","CVE-2023-2868","CVE-2023-29300","CVE-2023-34362","CVE-2023-3519","CVE-2023-38035","CVE-2023-38203","CVE-2023-38831","CVE-2023-48788","CVE-2023-7101","CVE-2024-23692","CVE-2024-4978","CVE-2025-31200","CVE-2025-31201","CVE-2025-43200"]},{"slug":"fs-quarantine","name":"fs:quarantine","channels":[{"channel":"/var/log/quarantine.log","analytics":["AN1462"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN1462"],"techniques":["T1036.002"],"platforms":["macOS"],"kev_cves":[]},{"slug":"wlanlogs-association","name":"WLANLogs:Association","channels":[{"channel":"Multiple APs advertising the same SSID but with different BSSID/MAC or encryption type","analytics":["AN1069"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN1069"],"techniques":["T1557.004"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"fs-filesystem","name":"fs:filesystem","channels":[{"channel":"Modification or creation of files matching 'com.apple.loginwindow.*.plist' in ~/Library/Preferences/ByHost","analytics":["AN0349"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN0349"],"techniques":["T1547.007"],"platforms":["macOS"],"kev_cves":[]},{"slug":"etw-microsoft-windows-security-auditing","name":"etw:Microsoft-Windows-Security-Auditing","channels":[{"channel":"api_call: LogonUser(A|W), LsaLogonUser, SetThreadToken, ImpersonateLoggedOnUser","analytics":["AN1375"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN1375"],"techniques":["T1134.003"],"platforms":["Windows"],"kev_cves":[]},{"slug":"firmware-integrity","name":"firmware:integrity ","channels":[{"channel":"Firmware integrity verification failures or mismatches against expected UEFI/firmware image baselines","analytics":["AN0916"],"data_components":["DC0004"]}],"data_components":["DC0004"],"analytics":["AN0916"],"techniques":["T1542.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"networkdevice-controlplane","name":"networkdevice:controlplane","channels":[{"channel":"Syslog from edge devices with HTTP 500s on mgmt portal, SmartInstall events, unexpected CLI commands","analytics":["AN0225"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0225"],"techniques":["T1190"],"platforms":["Network Devices"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"networkdevice-runtime","name":"networkdevice:runtime","channels":[{"channel":"Firmware image uploaded via TFTP/FTP/SCP","analytics":["AN0276"],"data_components":["DC0046"]},{"channel":"runtime","analytics":["AN0281"],"data_components":["DC0029"]}],"data_components":["DC0029","DC0046"],"analytics":["AN0276","AN0281"],"techniques":["T1059.011","T1542.001"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"prometheus-metrics","name":"prometheus:metrics","channels":[{"channel":"Container CPU/Memory usage exceeding threshold","analytics":["AN0745"],"data_components":["DC0018"]}],"data_components":["DC0018"],"analytics":["AN0745"],"techniques":["T1496"],"platforms":["Containers"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-32315","CVE-2023-38035","CVE-2023-47565","CVE-2023-49897","CVE-2024-23692","CVE-2025-4632"]},{"slug":"container-cni","name":"container:cni","channels":[{"channel":"Outbound network traffic to mining proxies","analytics":["AN0745"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0745"],"techniques":["T1496"],"platforms":["Containers"],"kev_cves":["CVE-2017-9822","CVE-2018-11776","CVE-2018-7600","CVE-2019-18935","CVE-2020-8515","CVE-2021-22205","CVE-2021-26084","CVE-2021-35394","CVE-2021-44228","CVE-2022-29303","CVE-2022-29464","CVE-2023-1389","CVE-2023-22527","CVE-2023-32315","CVE-2023-38035","CVE-2023-47565","CVE-2023-49897","CVE-2024-23692","CVE-2025-4632"]},{"slug":"fs-plist","name":"fs:plist","channels":[{"channel":"/var/root/Library/Preferences/com.apple.loginwindow.plist","analytics":["AN0682"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN0682"],"techniques":["T1037.002"],"platforms":["macOS"],"kev_cves":[]},{"slug":"desktop-file-manager","name":"desktop:file_manager","channels":[{"channel":"nautilus, dolphin, or gvfs logs","analytics":["AN1463"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN1463"],"techniques":["T1036.002"],"platforms":["Linux"],"kev_cves":[]},{"slug":"apache-access-log","name":"apache:access_log","channels":[{"channel":"Unusual HTTP POST or PUT requests to paths such as '/uploads/', '/admin/', or CMS plugin folders","analytics":["AN0663"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0663"],"techniques":["T1491"],"platforms":["Linux"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-smbclient-security","name":"WinEventLog:Microsoft-Windows-SMBClient/Security","channels":[{"channel":"EventCode=31001","analytics":["AN0194"],"data_components":["DC0102"]}],"data_components":["DC0102"],"analytics":["AN0194"],"techniques":["T1074.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-microsoft-office-alerts","name":"WinEventLog:Microsoft-Office-Alerts","channels":[{"channel":"Office application warning or alert on macro execution from template","analytics":["AN1436"],"data_components":["DC0064"]},{"channel":"Unexpected DLL or component loaded at Office startup","analytics":["AN0880"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0880","AN1436"],"techniques":["T1137.001","T1137.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"nsm-content","name":"NSM:Content","channels":[{"channel":"HTTP Header Metadata","analytics":["AN1296"],"data_components":["DC0085"]},{"channel":"TLS Fingerprint and Certificate Analysis","analytics":["AN1297"],"data_components":["DC0085"]},{"channel":"Traffic on RPC DRSUAPI","analytics":["AN1632"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1296","AN1297","AN1632"],"techniques":["T1001.003","T1003.006"],"platforms":["ESXi","Windows","macOS"],"kev_cves":[]},{"slug":"macos-launchd","name":"macos:launchd","channels":[{"channel":"launchd.plist and logs","analytics":["AN1120"],"data_components":["DC0005"]}],"data_components":["DC0005"],"analytics":["AN1120"],"techniques":["T1029"],"platforms":["macOS"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-wlan-autoconfig","name":"WinEventLog:Microsoft-Windows-WLAN-AutoConfig","channels":[{"channel":"EventCode=8001, 8002, 8003","analytics":["AN1476"],"data_components":["DC0082"]}],"data_components":["DC0082"],"analytics":["AN1476"],"techniques":["T1669"],"platforms":["Windows"],"kev_cves":[]},{"slug":"m365defender-devicenetworkevents","name":"M365Defender:DeviceNetworkEvents","channels":[{"channel":"NetworkConnection: bytes_sent >> bytes_received anomaly","analytics":["AN0345"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0345"],"techniques":["T1132.001"],"platforms":["Windows"],"kev_cves":[]},{"slug":"aws-cloudmetrics","name":"AWS:CloudMetrics","channels":[{"channel":"Autoscaling, memory/cpu alarms, or instance unhealthiness","analytics":["AN1168"],"data_components":["DC0018"]}],"data_components":["DC0018"],"analytics":["AN1168"],"techniques":["T1499.003"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"journald-package","name":"journald:package","channels":[{"channel":"dpkg/apt install, remove, upgrade events","analytics":["AN1481"],"data_components":["DC0059"]},{"channel":"dpkg/apt or yum/dnf transaction logs (install/update of build tools)","analytics":["AN0022"],"data_components":["DC0059"]},{"channel":"dpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journals","analytics":["AN0863"],"data_components":["DC0059"]}],"data_components":["DC0059"],"analytics":["AN0022","AN0863","AN1481"],"techniques":["T1195","T1195.001","T1195.002"],"platforms":["Linux"],"kev_cves":["CVE-2021-44529","CVE-2024-49035","CVE-2024-4978"]},{"slug":"saas-appsscript","name":"saas:appsscript","channels":[{"channel":"Create / Update: Deployment of scripts with event-driven triggers","analytics":["AN1055"],"data_components":["DC0069"]}],"data_components":["DC0069"],"analytics":["AN1055"],"techniques":["T1648"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"saas-googledrive","name":"saas:googledrive","channels":[{"channel":"FileOpen / FileAccess: Event-driven script triggering on user file actions","analytics":["AN1055"],"data_components":["DC0038"]},{"channel":"drive.permission.add","analytics":["AN1582"],"data_components":["DC0023"]}],"data_components":["DC0023","DC0038"],"analytics":["AN1055","AN1582"],"techniques":["T1537","T1648"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"wineventlog-kerberos","name":"WinEventLog:Kerberos","channels":[{"channel":"Kerberos TGS-REQ anomalies without KDC validation (Silver Ticket behavior)","analytics":["AN0675"],"data_components":["DC0084"]}],"data_components":["DC0084"],"analytics":["AN0675"],"techniques":["T1558.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"etw-microsoft-windows-rpc","name":"etw:Microsoft-Windows-RPC","channels":[{"channel":"rpc_call: srvsvc.NetShareEnum / NetShareEnumAll from non-admin or unusual processes","analytics":["AN0513"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0513"],"techniques":["T1135"],"platforms":["Windows"],"kev_cves":[]},{"slug":"windows-osquery","name":"windows:osquery","channels":[{"channel":"User enumeration with creation/last modified timestamps","analytics":["AN1077"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN1077"],"techniques":["T1036.010"],"platforms":["Windows"],"kev_cves":[]},{"slug":"etw-microsoft-windows-kernel-storage","name":"etw:Microsoft-Windows-Kernel-Storage","channels":[{"channel":"Raw disk I/O operations bypassing NTFS APIs","analytics":["AN1271"],"data_components":["DC0004"]}],"data_components":["DC0004"],"analytics":["AN1271"],"techniques":["T1564.005"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wids-associationlogs","name":"WIDS:AssociationLogs","channels":[{"channel":"Unauthorized AP or anomalous MAC address connection attempts","analytics":["AN1479"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1479"],"techniques":["T1669"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"vpxd-log","name":"vpxd.log","channels":[{"channel":"API communication","analytics":["AN1192"],"data_components":["DC0078"]},{"channel":"vCenter Management","analytics":["AN0849"],"data_components":["DC0013"]}],"data_components":["DC0013","DC0078"],"analytics":["AN0849","AN1192"],"techniques":["T1087.001","T1102"],"platforms":["ESXi"],"kev_cves":["CVE-2023-27532"]},{"slug":"auditd-mmap","name":"auditd:MMAP","channels":[{"channel":"load: Loading of libzip.so, libz.so, or libbz2.so by processes not normally associated with archiving","analytics":["AN0748"],"data_components":["DC0016"]},{"channel":"memory region with RWX permissions allocated","analytics":["AN0839"],"data_components":["DC0021"]}],"data_components":["DC0016","DC0021"],"analytics":["AN0748","AN0839"],"techniques":["T1560.002","T1620"],"platforms":["Linux"],"kev_cves":[]},{"slug":"saas-access","name":"saas:access","channels":[{"channel":"Multiple concurrent logins using same cookie from different locations","analytics":["AN0487"],"data_components":["DC0067"]},{"channel":"SAML token accepted without preceding login challenge","analytics":["AN0421"],"data_components":["DC0007"]}],"data_components":["DC0007","DC0067"],"analytics":["AN0421","AN0487"],"techniques":["T1606.001","T1606.002"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"macos-jamf","name":"macos:jamf","channels":[{"channel":"RemoteCommandExecution","analytics":["AN0625"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0625"],"techniques":["T1072"],"platforms":["macOS"],"kev_cves":[]},{"slug":"linux-fim","name":"linux:fim","channels":[{"channel":"Changes to /etc/rc.local.d/local.sh or creation of unexpected startup files in persistent partitions (/etc/init.d, /store, /locker)","analytics":["AN1475"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN1475"],"techniques":["T1505.006"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"m365-oauth","name":"m365:oauth","channels":[{"channel":"OAuth grants or tokens issued without expected user consent","analytics":["AN0723"],"data_components":["DC0006"]}],"data_components":["DC0006"],"analytics":["AN0723"],"techniques":["T1606"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"networkdevice-ids","name":"networkdevice:IDS","channels":[{"channel":"content inspection / PCAP / HTTP body","analytics":["AN1067"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1067"],"techniques":["T1027"],"platforms":["Network Devices"],"kev_cves":["CVE-2010-2883","CVE-2021-40449","CVE-2021-40539","CVE-2021-44077","CVE-2022-24086"]},{"slug":"wineventlog-microsoft-office-outlookaddinmonitor","name":"WinEventLog:Microsoft-Office/OutlookAddinMonitor","channels":[{"channel":"Outlook loading add-in via unexpected load path or non-default profile context","analytics":["AN0138"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0138"],"techniques":["T1137.006"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"cni-netflow","name":"cni:netflow","channels":[{"channel":"outbound connection to internal or external APIs","analytics":["AN0859"],"data_components":["DC0082"]}],"data_components":["DC0082"],"analytics":["AN0859"],"techniques":["T1552.001"],"platforms":["Containers"],"kev_cves":["CVE-2019-11510","CVE-2022-26138","CVE-2024-57727"]},{"slug":"wineventlog-winrm","name":"WinEventLog:WinRM","channels":[{"channel":"EventCode=6","analytics":["AN1313"],"data_components":["DC0041"]}],"data_components":["DC0041"],"analytics":["AN1313"],"techniques":["T1021.006"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-adminapi","name":"saas:adminapi","channels":[{"channel":"ListIntegrations, ListServices: Repeated service discovery requests from accounts without administrative responsibilities","analytics":["AN1130"],"data_components":["DC0083"]}],"data_components":["DC0083"],"analytics":["AN1130"],"techniques":["T1526"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-kernel-boot","name":"WinEventLog:Microsoft-Windows-Kernel-Boot","channels":[{"channel":"Firmware integrity validation failed or boot configuration tampered","analytics":["AN0474"],"data_components":["DC0004"]}],"data_components":["DC0004"],"analytics":["AN0474"],"techniques":["T1495"],"platforms":["Windows"],"kev_cves":["CVE-2024-54085","CVE-2025-21480"]},{"slug":"applicationlog-webserver","name":"ApplicationLog:WebServer","channels":[{"channel":"/var/log/httpd/access_log, /var/log/apache2/access.log, /var/log/nginx/access.log with exploit indicators and burst errors","analytics":["AN0220"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0220"],"techniques":["T1190"],"platforms":["Linux"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"m365-audit","name":"m365:audit","channels":[{"channel":"Add member to role, Add app role assignment","analytics":["AN0772"],"data_components":["DC0010"]}],"data_components":["DC0010"],"analytics":["AN0772"],"techniques":["T1098.003"],"platforms":["Identity Provider"],"kev_cves":[]},{"slug":"applicationlog-ingress","name":"ApplicationLog:Ingress","channels":[{"channel":"Kubernetes NGINX/Envoy ingress controller logs with anomalous payloads and 5xx spikes","analytics":["AN0222"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0222"],"techniques":["T1190"],"platforms":["Containers"],"kev_cves":["CVE-2009-3960","CVE-2010-2861","CVE-2013-0625","CVE-2013-0629","CVE-2013-0631","CVE-2013-0632","CVE-2014-6271","CVE-2014-7169","CVE-2016-10033","CVE-2016-4437","CVE-2017-12637","CVE-2017-5638","CVE-2017-9805","CVE-2017-9822","CVE-2018-11776","CVE-2018-13379","CVE-2018-15961","CVE-2018-4939","CVE-2018-6789","CVE-2018-7600","CVE-2019-0604","CVE-2019-11634","CVE-2019-1653","CVE-2019-17558","CVE-2019-18935","CVE-2020-0688","CVE-2020-15505","CVE-2020-17530","CVE-2020-29557","CVE-2020-5902","CVE-2021-21972","CVE-2021-21973","CVE-2021-21975","CVE-2021-22005","CVE-2021-22017","CVE-2021-22204","CVE-2021-22205","CVE-2021-22893","CVE-2021-22986","CVE-2021-26085","CVE-2021-26858","CVE-2021-27065","CVE-2021-27102","CVE-2021-27103","CVE-2021-27104","CVE-2021-27860","CVE-2021-31166","CVE-2021-3129","CVE-2021-34473","CVE-2021-34523","CVE-2021-35394","CVE-2021-35464","CVE-2021-36380","CVE-2021-37415","CVE-2021-39144","CVE-2021-39226","CVE-2021-40539","CVE-2021-40655","CVE-2021-44077","CVE-2021-44228","CVE-2021-44515","CVE-2021-44529","CVE-2021-45382","CVE-2022-0028","CVE-2022-1040","CVE-2022-20700","CVE-2022-20708","CVE-2022-20821","CVE-2022-22947","CVE-2022-22963","CVE-2022-22965","CVE-2022-23131","CVE-2022-24086","CVE-2022-26134","CVE-2022-26258","CVE-2022-26500","CVE-2022-26501","CVE-2022-28810","CVE-2022-29464","CVE-2022-35914","CVE-2022-36804","CVE-2022-39197","CVE-2022-40684","CVE-2022-42475","CVE-2022-42948","CVE-2022-43939","CVE-2022-47966","CVE-2023-0669","CVE-2023-20198","CVE-2023-20887","CVE-2023-22515","CVE-2023-22518","CVE-2023-22952","CVE-2023-26359","CVE-2023-26360","CVE-2023-27350","CVE-2023-27524","CVE-2023-27997","CVE-2023-29298","CVE-2023-29300","CVE-2023-29492","CVE-2023-33246","CVE-2023-34362","CVE-2023-35078","CVE-2023-35081","CVE-2023-3519","CVE-2023-36844","CVE-2023-36845","CVE-2023-36846","CVE-2023-36847","CVE-2023-36851","CVE-2023-38035","CVE-2023-38203","CVE-2023-38205","CVE-2023-38950","CVE-2023-42793","CVE-2023-44487","CVE-2023-46604","CVE-2023-46805","CVE-2023-48365","CVE-2023-48788","CVE-2023-49103","CVE-2023-7101","CVE-2024-0769","CVE-2024-13159","CVE-2024-13160","CVE-2024-13161","CVE-2024-20353","CVE-2024-20953","CVE-2024-21762","CVE-2024-21887","CVE-2024-21893","CVE-2024-27198","CVE-2024-34102","CVE-2024-38475","CVE-2024-4358","CVE-2024-4577","CVE-2024-48248","CVE-2024-4879","CVE-2024-55550","CVE-2024-57727","CVE-2025-0108","CVE-2025-0282","CVE-2025-1316","CVE-2025-22457","CVE-2025-23006","CVE-2025-25257","CVE-2025-34028","CVE-2025-35939","CVE-2025-42599","CVE-2025-42999","CVE-2025-4427","CVE-2025-4428","CVE-2025-49704","CVE-2025-49706","CVE-2025-53770","CVE-2025-5777"]},{"slug":"gcp-config","name":"gcp:config","channels":[{"channel":"UpdateSink request modifying log export destinations","analytics":["AN0801"],"data_components":["DC0069"]}],"data_components":["DC0069"],"analytics":["AN0801"],"techniques":["T1685.002"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"snmp-status","name":"snmp:status","channels":[{"channel":"Status change in cryptographic hardware modules (enabled -> disabled)","analytics":["AN0961"],"data_components":["DC0016"]}],"data_components":["DC0016"],"analytics":["AN0961"],"techniques":["T1600"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"netflow-flow","name":"NetFlow:Flow","channels":[{"channel":"new outbound connections from exploited process tree","analytics":["AN0798"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0798"],"techniques":["T1203"],"platforms":["Linux"],"kev_cves":["CVE-2015-5119","CVE-2018-4939","CVE-2021-21148","CVE-2021-21166","CVE-2021-21206","CVE-2021-27059","CVE-2021-29256","CVE-2021-30554","CVE-2021-37975","CVE-2021-39144","CVE-2022-20701","CVE-2022-20703","CVE-2022-23748","CVE-2022-41128","CVE-2022-43769","CVE-2023-21608","CVE-2023-23397","CVE-2023-26369","CVE-2023-34048","CVE-2023-36844","CVE-2023-47565","CVE-2023-49897","CVE-2024-11120","CVE-2024-26169","CVE-2024-45195","CVE-2024-5274","CVE-2025-24016","CVE-2025-24993","CVE-2025-27038","CVE-2025-2783","CVE-2025-30397","CVE-2025-30406","CVE-2025-31200","CVE-2025-31201","CVE-2025-3248","CVE-2025-3935","CVE-2025-42999","CVE-2025-43200","CVE-2025-4427","CVE-2025-5419","CVE-2025-6543","CVE-2025-6554","CVE-2025-6558"]},{"slug":"auditd-fs","name":"auditd:FS","channels":[{"channel":"read: File access to /proc/modules or /sys/module/","analytics":["AN1596"],"data_components":["DC0055"]}],"data_components":["DC0055"],"analytics":["AN1596"],"techniques":["T1652"],"platforms":["Linux"],"kev_cves":[]},{"slug":"etw-token","name":"ETW:Token","channels":[{"channel":"api_call: DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken","analytics":["AN1324"],"data_components":["DC0021"]},{"channel":"token_analysis: API calls such as DuplicateTokenEx or ImpersonateLoggedOnUser","analytics":["AN0786"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0786","AN1324"],"techniques":["T1134","T1134.001"],"platforms":["Windows"],"kev_cves":["CVE-2023-4966"]},{"slug":"etw","name":"ETW","channels":[{"channel":"Calls to GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList","analytics":["AN1561"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN1561"],"techniques":["T1614.001"],"platforms":["Windows"],"kev_cves":[]},{"slug":"edr-telemetry","name":"EDR:Telemetry","channels":[{"channel":"Process lineage and API usage enrichment (GetSystemTime, GetTimeZoneInformation, NtQuerySystemTime)","analytics":["AN0430"],"data_components":["DC0034"]}],"data_components":["DC0034"],"analytics":["AN0430"],"techniques":["T1124"],"platforms":["Windows"],"kev_cves":[]},{"slug":"cloudtrail-putobject","name":"CloudTrail:PutObject","channels":[{"channel":"PutObject","analytics":["AN0666"],"data_components":["DC0039"]}],"data_components":["DC0039"],"analytics":["AN0666"],"techniques":["T1491"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"firmware-runtime","name":"firmware:runtime","channels":[{"channel":"Debug or memory access commands indicating attempts to alter OS instructions in memory","analytics":["AN1293"],"data_components":["DC0004"]}],"data_components":["DC0004"],"analytics":["AN1293"],"techniques":["T1601.001"],"platforms":["Network Devices"],"kev_cves":[]},{"slug":"wineventlog-windows-defender","name":"WinEventLog:Windows Defender","channels":[{"channel":"Operational","analytics":["AN1461"],"data_components":["DC0059"]},{"channel":"Operational log","analytics":["AN0089"],"data_components":["DC0059"]}],"data_components":["DC0059"],"analytics":["AN0089","AN1461"],"techniques":["T1036.001","T1036.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"auditd-memprotect","name":"auditd:memprotect","channels":[{"channel":"change from PROT_READ|PROT_WRITE to PROT_EXEC","analytics":["AN1241"],"data_components":["DC0020"]}],"data_components":["DC0020"],"analytics":["AN1241"],"techniques":["T1055.014"],"platforms":["Linux"],"kev_cves":[]},{"slug":"auditd-file-events","name":"auditd:file-events","channels":[{"channel":"open of suspicious .so from non-standard paths","analytics":["AN1241"],"data_components":["DC0016"]}],"data_components":["DC0016"],"analytics":["AN1241"],"techniques":["T1055.014"],"platforms":["Linux"],"kev_cves":[]},{"slug":"esxilogs-messages","name":"ESXiLogs:messages","channels":[{"channel":"changes to /etc/motd or /etc/vmware/welcome","analytics":["AN0232"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN0232"],"techniques":["T1491.001"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"etw-microsoft-windows-directory-services-sam","name":"etw:Microsoft-Windows-Directory-Services-SAM","channels":[{"channel":"api_call: Calls to DsAddSidHistory or related RPC operations","analytics":["AN0383"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0383"],"techniques":["T1134.005"],"platforms":["Windows"],"kev_cves":[]},{"slug":"linux-shell","name":"linux:shell","channels":[{"channel":"Manual invocation of software enumeration commands via interactive shell","analytics":["AN1101"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN1101"],"techniques":["T1518"],"platforms":["Linux"],"kev_cves":[]},{"slug":"macos-fsevents","name":"macos:fsevents","channels":[{"channel":"/Library/StartupItems/, ~/Library/LaunchAgents/","analytics":["AN1197"],"data_components":["DC0039"]}],"data_components":["DC0039"],"analytics":["AN1197"],"techniques":["T1037.005"],"platforms":["macOS"],"kev_cves":[]},{"slug":"snmp-trap","name":"snmp:trap","channels":[{"channel":"management queries","analytics":["AN0907"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0907"],"techniques":["T1049"],"platforms":["Network Devices"],"kev_cves":["CVE-2022-41328"]},{"slug":"auditd-daemon","name":"auditd:DAEMON","channels":[{"channel":"auditd stopped, config changed, logging suspended","analytics":["AN2039"],"data_components":["DC0041"]}],"data_components":["DC0041"],"analytics":["AN2039"],"techniques":["T1687"],"platforms":["Linux"],"kev_cves":[]},{"slug":"snmp-syslog","name":"snmp:syslog","channels":[{"channel":"firmware write/log event","analytics":["AN0169"],"data_components":["DC0039"]}],"data_components":["DC0039"],"analytics":["AN0169"],"techniques":["T1105"],"platforms":["Network Devices"],"kev_cves":["CVE-2010-0188","CVE-2010-1297","CVE-2010-2861","CVE-2011-0611","CVE-2012-0754","CVE-2012-1535","CVE-2013-0641","CVE-2015-5119","CVE-2015-8651","CVE-2016-0984","CVE-2016-1019","CVE-2016-4117","CVE-2017-11292","CVE-2018-15982","CVE-2021-35394","CVE-2021-44515","CVE-2022-30190","CVE-2023-20867","CVE-2023-22518","CVE-2023-26360","CVE-2023-27350","CVE-2023-2868","CVE-2023-29300","CVE-2023-34362","CVE-2023-3519","CVE-2023-38035","CVE-2023-38203","CVE-2023-38831","CVE-2023-48788","CVE-2023-7101","CVE-2024-23692","CVE-2024-4978","CVE-2025-31200","CVE-2025-31201","CVE-2025-43200"]},{"slug":"fs-plist-monitoring","name":"fs:plist_monitoring","channels":[{"channel":"/Users/*/Library/Mail/V*/MailData/RulesActiveState.plist","analytics":["AN1590"],"data_components":["DC0061"]}],"data_components":["DC0061"],"analytics":["AN1590"],"techniques":["T1114.003"],"platforms":["macOS"],"kev_cves":[]},{"slug":"windows-firewall-log","name":"Windows Firewall Log","channels":[{"channel":"SMB over high port","analytics":["AN0204"],"data_components":["DC0078"]}],"data_components":["DC0078"],"analytics":["AN0204"],"techniques":["T1090.001"],"platforms":["Windows"],"kev_cves":["CVE-2021-22017"]},{"slug":"applicationlog-callrecords","name":"ApplicationLog:CallRecords","channels":[{"channel":"Outbound or inbound calls to high-risk or blocklisted numbers","analytics":["AN0683"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0683"],"techniques":["T1566.004"],"platforms":["Windows"],"kev_cves":[]},{"slug":"esxilogs-authlog","name":"ESXiLogs:authlog","channels":[{"channel":"Unexpected login followed by encoding commands","analytics":["AN0305"],"data_components":["DC0002"]}],"data_components":["DC0002"],"analytics":["AN0305"],"techniques":["T1132"],"platforms":["ESXi"],"kev_cves":[]},{"slug":"etw-microsoft-windows-kernel-base","name":"etw:Microsoft-Windows-Kernel-Base","channels":[{"channel":"GetLocaleInfoW, GetTimeZoneInformation API calls","analytics":["AN0119"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0119"],"techniques":["T1614"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-tcpip","name":"WinEventLog:Microsoft-Windows-TCPIP","channels":[{"channel":"Connection queue overflow or failure to allocate TCP state object","analytics":["AN1012"],"data_components":["DC0018"]}],"data_components":["DC0018"],"analytics":["AN1012"],"techniques":["T1499.001"],"platforms":["Windows"],"kev_cves":[]},{"slug":"saas-app-auth","name":"saas-app:auth","channels":[{"channel":"login_failure","analytics":["AN1266"],"data_components":["DC0002"]}],"data_components":["DC0002"],"analytics":["AN1266"],"techniques":["T1110.004"],"platforms":["SaaS"],"kev_cves":[]},{"slug":"applicationlog-intune-mdm-logs","name":"ApplicationLog:Intune/MDM Logs","channels":[{"channel":"Enrollment events (e.g., MDMDeviceRegistration)","analytics":["AN0104"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN0104"],"techniques":["T1098.005"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-applocker","name":"WinEventLog:AppLocker","channels":[{"channel":"AppLocker audit/blocks showing developer utilities executing scripts/binaries outside policy","analytics":["AN0488"],"data_components":["DC0034"]}],"data_components":["DC0034"],"analytics":["AN0488"],"techniques":["T1127"],"platforms":["Windows"],"kev_cves":[]},{"slug":"edr-cli","name":"EDR:cli","channels":[{"channel":"Command Line Telemetry","analytics":["AN0133"],"data_components":["DC0064"]}],"data_components":["DC0064"],"analytics":["AN0133"],"techniques":["T1070.007"],"platforms":["Windows"],"kev_cves":[]},{"slug":"azure-vmguest","name":"azure:vmguest","channels":[{"channel":"Unexpected execution of cloud agent processes (e.g., WindowsAzureGuestAgent.exe, ssm-agent) followed by arbitrary script or binary execution","analytics":["AN1502"],"data_components":["DC0032"]}],"data_components":["DC0032"],"analytics":["AN1502"],"techniques":["T1651"],"platforms":["IaaS"],"kev_cves":[]},{"slug":"etw-microsoft-windows-kernel-file","name":"etw:Microsoft-Windows-Kernel-File","channels":[{"channel":"ZwSetEaFile or ZwQueryEaFile function calls","analytics":["AN1206"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN1206"],"techniques":["T1564.004"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-security-mitigations-kernelmode","name":"WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode","channels":[{"channel":"ETW telemetry indicating ClickOnce deployment (dfsvc.exe) launching payloads","analytics":["AN0550"],"data_components":["DC0034"]}],"data_components":["DC0034"],"analytics":["AN0550"],"techniques":["T1127.002"],"platforms":["Windows"],"kev_cves":[]},{"slug":"docker-registry","name":"docker:registry","channels":[{"channel":"push event of new image version from unrecognized user or context","analytics":["AN0946"],"data_components":["DC0036"]}],"data_components":["DC0036"],"analytics":["AN0946"],"techniques":["T1525"],"platforms":["Containers"],"kev_cves":[]},{"slug":"systemd-unit","name":"systemd:unit","channels":[{"channel":"container run with restart policy set to 'always' or 'unless-stopped'","analytics":["AN1304"],"data_components":["DC0072"]}],"data_components":["DC0072"],"analytics":["AN1304"],"techniques":["T1543.005"],"platforms":["Containers"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-backup","name":"WinEventLog:Microsoft-Windows-Backup","channels":[{"channel":"Windows Backup Catalog deletion or catalog corruption","analytics":["AN0933"],"data_components":["DC0040"]}],"data_components":["DC0040"],"analytics":["AN0933"],"techniques":["T1490"],"platforms":["Windows"],"kev_cves":["CVE-2023-36884","CVE-2025-21391"]},{"slug":"edr-amsi","name":"EDR:AMSI","channels":[{"channel":"Malicious inline C#/script blobs embedded in MSBuild projects if intercepted by AMSI-aware loaders (rare but possible via chained LOLBins)","analytics":["AN1535"],"data_components":["DC0029"]},{"channel":"None","analytics":["AN0012"],"data_components":["DC0064"]}],"data_components":["DC0029","DC0064"],"analytics":["AN0012","AN1535"],"techniques":["T1036.003","T1127.001"],"platforms":["Windows"],"kev_cves":[]},{"slug":"auditd-auth","name":"auditd:AUTH","channels":[{"channel":"pam_unix or pam_google_authenticator invoked repeatedly within short interval","analytics":["AN0452"],"data_components":["DC0002"]}],"data_components":["DC0002"],"analytics":["AN0452"],"techniques":["T1621"],"platforms":["Linux"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-com-operational","name":"WinEventLog:Microsoft-Windows-COM/Operational","channels":[{"channel":"CLSID activation events where ProcessName=mmc.exe and CLSID not in allowed baseline","analytics":["AN0622"],"data_components":["DC0021"]}],"data_components":["DC0021"],"analytics":["AN0622"],"techniques":["T1218.014"],"platforms":["Windows"],"kev_cves":[]},{"slug":"gcp-vpcflow","name":"gcp:vpcflow","channels":[{"channel":"first 5m egress to unknown ASNs","analytics":["AN1318"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN1318"],"techniques":["T1204"],"platforms":["IaaS"],"kev_cves":["CVE-2023-38831","CVE-2025-24993"]},{"slug":"saas-email","name":"saas:email","channels":[{"channel":"AuthenticationFailures (SPF/DKIM/DMARC) OR Domain Mismatch","analytics":["AN1205"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN1205"],"techniques":["T1684.002"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"autoruns-registryscan","name":"Autoruns:RegistryScan","channels":[{"channel":"Enumerate Winlogon subkeys for unknown or unsigned binaries","analytics":["AN1133"],"data_components":["DC0050"]}],"data_components":["DC0050"],"analytics":["AN1133"],"techniques":["T1547.004"],"platforms":["Windows"],"kev_cves":[]},{"slug":"wineventlog-microsoft-windows-shell-core","name":"WinEventLog:Microsoft-Windows-Shell-Core","channels":[{"channel":"New startup folder shortcut or binary placed in Startup directory","analytics":["AN1032"],"data_components":["DC0039"]}],"data_components":["DC0039"],"analytics":["AN1032"],"techniques":["T1547.001"],"platforms":["Windows"],"kev_cves":["CVE-2022-22047"]},{"slug":"sar-network","name":"sar:network","channels":[{"channel":"Outbound network saturation with minimal process activity","analytics":["AN1141"],"data_components":["DC0018"]}],"data_components":["DC0018"],"analytics":["AN1141"],"techniques":["T1498.002"],"platforms":["Linux"],"kev_cves":[]},{"slug":"okta-systemlog","name":"Okta:SystemLog","channels":[{"channel":"eventType: user.authentication.sso, app.oauth2.token.grant","analytics":["AN0215"],"data_components":["DC0002"]},{"channel":"user.authentication.sso, app.oauth.grant","analytics":["AN0018"],"data_components":["DC0067"]}],"data_components":["DC0002","DC0067"],"analytics":["AN0018","AN0215"],"techniques":["T1021.007","T1059.009"],"platforms":["IaaS","Identity Provider"],"kev_cves":[]},{"slug":"m365-teams","name":"m365:teams","channels":[{"channel":"External chat request or new tenant communication preceding approval activity","analytics":["AN2033"],"data_components":["DC0038"]}],"data_components":["DC0038"],"analytics":["AN2033"],"techniques":["T1684"],"platforms":["Office Suite"],"kev_cves":[]},{"slug":"container-proxy","name":"container:proxy","channels":[{"channel":"outbound/inbound network activity from spawned pods","analytics":["AN0582"],"data_components":["DC0085"]}],"data_components":["DC0085"],"analytics":["AN0582"],"techniques":["T1053.007"],"platforms":["Containers"],"kev_cves":[]},{"slug":"microsoft-entra-id-audit-logs","name":"Microsoft Entra ID Audit Logs","channels":[{"channel":"RoleManagement.Read.Directory or Directory.Read.All","analytics":["AN1087"],"data_components":["DC0013"]}],"data_components":["DC0013"],"analytics":["AN1087"],"techniques":["T1087.004"],"platforms":["Identity Provider"],"kev_cves":[]},{"slug":"apple-tcc-logs","name":"Apple TCC Logs","channels":[{"channel":"Microphone Access Events","analytics":["AN0621"],"data_components":["DC0035"]}],"data_components":["DC0035"],"analytics":["AN0621"],"techniques":["T1123"],"platforms":["macOS"],"kev_cves":[]}]}