{"id":"T1654","name":"Log Enumeration","url":"https://attack.mitre.org/techniques/T1654","tactics":["discovery"],"platforms":["ESXi","IaaS","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0255","stix_id":"x-mitre-detection-strategy--170a958d-79a6-433a-8ab0-c8d654e2ca86","name":"Detection Strategy for Log Enumeration","url":"https://attack.mitre.org/detectionstrategies/DET0255","analytics":[{"id":"AN0705","stix_id":"x-mitre-analytic--13810047-61f4-4cd0-aeda-6727d652da90","name":"Analytic 0705","description":"Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity.","url":"https://attack.mitre.org/detectionstrategies/DET0255#AN0705","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"WhitelistedAdminTools","description":"Expected log management scripts executed by administrators should be excluded from alerts."},{"field":"TimeWindow","description":"Correlate enumeration attempts with file export or network transfer within a defined timeframe."}],"live":true,"detection_strategies":["DET0255"],"techniques":["T1654"]},{"id":"AN0706","stix_id":"x-mitre-analytic--ee468e26-d179-47ba-af8b-43118db24939","name":"Analytic 0706","description":"Monitor for suspicious use of commands such as cat, less, grep, or journalctl accessing /var/log/ files. Abnormal enumeration of authentication logs (auth.log, secure) or bulk access to multiple logs in short time windows should be flagged.","url":"https://attack.mitre.org/detectionstrategies/DET0255#AN0706","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of cat, less, grep, journalctl targeting log directories (/var/log/)","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"open: Access to sensitive log files (/var/log/auth.log, /var/log/secure, /var/log/syslog)","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"AdminMaintenanceScripts","description":"Filter routine scripts used for log rotation or troubleshooting."}],"live":true,"detection_strategies":["DET0255"],"techniques":["T1654"]},{"id":"AN0707","stix_id":"x-mitre-analytic--8f998965-ad70-4ec6-8bc1-85831edc0497","name":"Analytic 0707","description":"Detect abnormal access to unified logs via log show or fs_usage targeting system log files. Monitor for execution of shell utilities (cat, grep) against /var/log/system.log and for plist modifications enabling verbose logging.","url":"https://attack.mitre.org/detectionstrategies/DET0255#AN0707","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of log show, fs_usage, or cat targeting system.log","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"open: Access to /var/log/system.log or related security event logs","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DebugToolsContext","description":"Allowlist developers or administrators expected to review logs during debugging."}],"live":true,"detection_strategies":["DET0255"],"techniques":["T1654"]},{"id":"AN0708","stix_id":"x-mitre-analytic--42bae633-1033-40da-bf3a-87bcd1b0297f","name":"Analytic 0708","description":"Monitor for cloud API calls that export or collect guest or system logs. Abnormal use of Azure VM Agent’s CollectGuestLogs.exe or AWS CloudWatch GetLogEvents across multiple instances should be correlated with lateral movement or data staging.","url":"https://attack.mitre.org/detectionstrategies/DET0255#AN0708","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"GetLogEvents: High frequency log exports from CloudWatch or equivalent services","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"aws-cloudtrail"},{"name":"azure:activity","channel":"CollectGuestLogs: Unexpected collection of guest logs by Azure VM Agent outside normal maintenance windows","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"azure-activity"}],"mutable_elements":[{"field":"LogExportThreshold","description":"Define thresholds for volume/frequency of log export requests considered suspicious."}],"live":true,"detection_strategies":["DET0255"],"techniques":["T1654"]},{"id":"AN0709","stix_id":"x-mitre-analytic--f5b9ad98-3a10-4ff3-9e25-890488253bef","name":"Analytic 0709","description":"Monitor ESXi shell or API access to host logs under /var/log/. Abnormal enumeration of vmkernel.log, hostd.log, or vpxa.log by unauthorized accounts should be flagged.","url":"https://attack.mitre.org/detectionstrategies/DET0255#AN0709","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"Execution of cat, tail, grep targeting /var/log/vmkernel.log or /var/log/hostd.log","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"esxi:hostd","channel":"read: Access to sensitive log files by non-admin users","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"AdminSessions","description":"Correlate with legitimate administrator access sessions to reduce noise."}],"live":true,"detection_strategies":["DET0255"],"techniques":["T1654"]}],"live":true,"version":"1.0","techniques":["T1654"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}