Log sources › auditd:EXECVE
auditd:EXECVE
Inverted view: what can be detected if this is the log you have. Linux
35
channels
45
analytics
44
techniques
21
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/usr/sbin/postfix, /usr/sbin/exim, /usr/sbin/sendmail |
DC0032 Process Creation | AN0473 | 1 |
EXECVE |
DC0032 Process Creation | AN0056 AN1418 AN1638 | 3 |
Execution of GUI-related binaries with suppressed window/display flags |
DC0064 Command Execution | AN0361 | 1 |
Execution of auditctl, systemctl stop auditd, or kill -9 auditd |
DC0064 Command Execution | AN0171 | 1 |
Execution of chattr to set +i or +a attributes |
DC0064 Command Execution | AN1385 | 1 |
Execution of dd, shred, or wipe with arguments targeting block devices |
DC0032 Process Creation | AN0883 | 1 |
Execution of dd, shred, wipe targeting block devices |
DC0032 Process Creation | AN0385 | 1 |
Execution of dd/sgdisk with arguments writing to sector 0 or partition table |
DC0032 Process Creation | AN0828 | 1 |
Execution of gsettings set org.gnome.login-screen disable-user-list true |
DC0064 Command Execution | AN1002 | 1 |
Execution of ssh/scp/sftp without corresponding authentication log |
DC0032 Process Creation | AN0710 | 1 |
None |
DC0032 Process Creation | AN0505 AN1062 | 2 |
Process execution of update-ca-certificates or openssl with suspicious arguments |
DC0064 Command Execution | AN1247 | 1 |
Process execution via .desktop Exec path from /etc/xdg/autostart or ~/.config/autostart |
DC0032 Process Creation | AN1096 | 1 |
Use of mv or cp to rename files with '.' prefix |
DC0064 Command Execution | AN0092 | 1 |
cat|less|grep accessing .bash_history from a non-shell process |
DC0032 Process Creation | AN1085 | 1 |
command line arguments containing lsblk, fdisk, parted |
DC0064 Command Execution | AN0537 | 1 |
curl -T, rclone copy |
DC0064 Command Execution | AN1572 | 1 |
curl -X POST, wget --post-data |
DC0064 Command Execution | AN0437 | 1 |
curl -d, wget --post-data |
DC0064 Command Execution | AN0788 | 1 |
curl or wget with POST/PUT options |
DC0064 Command Execution | AN1512 | 1 |
exec: Execution of dd, efibootmgr, or flashrom modifying firmware/boot partitions |
DC0064 Command Execution | AN0775 | 1 |
execution of setfattr or getfattr commands |
DC0064 Command Execution | AN1135 | 1 |
execution of systemctl with subcommands start, stop, enable, disable |
DC0064 Command Execution | AN0200 | 1 |
execution of unexpected binaries during user shell startup |
DC0032 Process Creation | AN0059 | 1 |
execve |
DC0032 Process Creation | AN0272 AN0560 AN0950 AN1016 AN1199 AN1281 AN1326 AN1517 AN1584 | 9 |
execve of curl,wget,bash,sh,python with piped or remote content |
DC0064 Command Execution | AN2037 | 1 |
execve of script/interpreter (bash, python, node) with suspicious encoded or non-printable content |
DC0064 Command Execution | AN2064 | 1 |
execve, kill, ptrace, insmod, rmmod targeting security processes |
DC0064 Command Execution | AN2039 | 1 |
execve: Execution of update-ca-certificates or trust anchor modification commands |
DC0064 Command Execution | AN0154 | 1 |
execve: Processes launched with LD_PRELOAD/LD_LIBRARY_PATH pointing to non-system dirs |
DC0032 Process Creation | AN0053 | 1 |
gcore, gdb, strings, hexdump execution |
DC0064 Command Execution | AN0157 | 1 |
git push, curl -X POST |
DC0064 Command Execution | AN0896 | 1 |
grep/cat/awk on files with password fields |
DC0064 Command Execution | AN0857 | 1 |
systemctl spawning managed processes |
DC0032 Process Creation | AN0200 | 1 |
systemctl stop auditd, kill -9 <pid>, or modifications to /etc/selinux/config |
DC0032 Process Creation | AN0887 | 0 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2017-12637 | SAP NetWeaver | T1555 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1552.001 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1007 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1016 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1567 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1555 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1018 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1555 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1567 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1555 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1555 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1552.001 T1552.004 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1018 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1555 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1555 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1555 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1567 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1555 | Mapped |