kevmap

Log sources › auditd:EXECVE

auditd:EXECVE

Inverted view: what can be detected if this is the log you have. Linux

35
channels
45
analytics
44
techniques
21
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/usr/sbin/postfix, /usr/sbin/exim, /usr/sbin/sendmail DC0032 Process Creation AN0473 1
EXECVE DC0032 Process Creation AN0056 AN1418 AN1638 3
Execution of GUI-related binaries with suppressed window/display flags DC0064 Command Execution AN0361 1
Execution of auditctl, systemctl stop auditd, or kill -9 auditd DC0064 Command Execution AN0171 1
Execution of chattr to set +i or +a attributes DC0064 Command Execution AN1385 1
Execution of dd, shred, or wipe with arguments targeting block devices DC0032 Process Creation AN0883 1
Execution of dd, shred, wipe targeting block devices DC0032 Process Creation AN0385 1
Execution of dd/sgdisk with arguments writing to sector 0 or partition table DC0032 Process Creation AN0828 1
Execution of gsettings set org.gnome.login-screen disable-user-list true DC0064 Command Execution AN1002 1
Execution of ssh/scp/sftp without corresponding authentication log DC0032 Process Creation AN0710 1
None DC0032 Process Creation AN0505 AN1062 2
Process execution of update-ca-certificates or openssl with suspicious arguments DC0064 Command Execution AN1247 1
Process execution via .desktop Exec path from /etc/xdg/autostart or ~/.config/autostart DC0032 Process Creation AN1096 1
Use of mv or cp to rename files with '.' prefix DC0064 Command Execution AN0092 1
cat|less|grep accessing .bash_history from a non-shell process DC0032 Process Creation AN1085 1
command line arguments containing lsblk, fdisk, parted DC0064 Command Execution AN0537 1
curl -T, rclone copy DC0064 Command Execution AN1572 1
curl -X POST, wget --post-data DC0064 Command Execution AN0437 1
curl -d, wget --post-data DC0064 Command Execution AN0788 1
curl or wget with POST/PUT options DC0064 Command Execution AN1512 1
exec: Execution of dd, efibootmgr, or flashrom modifying firmware/boot partitions DC0064 Command Execution AN0775 1
execution of setfattr or getfattr commands DC0064 Command Execution AN1135 1
execution of systemctl with subcommands start, stop, enable, disable DC0064 Command Execution AN0200 1
execution of unexpected binaries during user shell startup DC0032 Process Creation AN0059 1
execve DC0032 Process Creation AN0272 AN0560 AN0950 AN1016 AN1199 AN1281 AN1326 AN1517 AN1584 9
execve of curl,wget,bash,sh,python with piped or remote content DC0064 Command Execution AN2037 1
execve of script/interpreter (bash, python, node) with suspicious encoded or non-printable content DC0064 Command Execution AN2064 1
execve, kill, ptrace, insmod, rmmod targeting security processes DC0064 Command Execution AN2039 1
execve: Execution of update-ca-certificates or trust anchor modification commands DC0064 Command Execution AN0154 1
execve: Processes launched with LD_PRELOAD/LD_LIBRARY_PATH pointing to non-system dirs DC0032 Process Creation AN0053 1
gcore, gdb, strings, hexdump execution DC0064 Command Execution AN0157 1
git push, curl -X POST DC0064 Command Execution AN0896 1
grep/cat/awk on files with password fields DC0064 Command Execution AN0857 1
systemctl spawning managed processes DC0032 Process Creation AN0200 1
systemctl stop auditd, kill -9 <pid>, or modifications to /etc/selinux/config DC0032 Process Creation AN0887 0

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1003.005 Cached Domain Credentialscredential access80
T1007 System Service Discoverydiscovery111
T1010 Application Window Discoverydiscovery10
T1014 Rootkitstealth10
T1016 System Network Configuration Discoverydiscovery121
T1016.001 Internet Connection Discoverydiscovery00
T1016.002 Wi-Fi Discoverydiscovery00
T1018 Remote System Discoverydiscovery172
T1021.004 SSHlateral movement52
T1021.005 VNClateral movement10
T1027.008 Stripped Payloadsstealth00
T1027.018 Invisible Unicodestealth00
T1129 Shared Modulesexecution20
T1505.002 Transport Agentpersistence30
T1542 Pre-OS Bootstealth, persistence00
T1546.004 Unix Shell Configuration Modificationprivilege escalation, persistence10
T1547.013 XDG Autostart Entriespersistence, privilege escalation00
T1552.001 Credentials In Filescredential access243
T1552.003 Shell Historycredential access30
T1552.004 Private Keyscredential access71
T1553 Subvert Trust Controlsdefense impairment40
T1553.004 Install Root Certificatedefense impairment100
T1554 Compromise Host Software Binarypersistence60
T1555 Credentials from Password Storescredential access89
T1555.002 Securityd Memorycredential access00
T1561 Disk Wipeimpact00
T1561.001 Disk Content Wipeimpact10
T1561.002 Disk Structure Wipeimpact10
T1563.001 SSH Hijackinglateral movement00
T1564 Hide Artifactsstealth100
T1564.001 Hidden Files and Directoriesstealth90
T1564.002 Hidden Usersstealth40
T1564.003 Hidden Windowstealth80
T1564.014 Extended Attributesstealth00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1569.003 Systemctlexecution00
T1680 Local Storage Discoverydiscovery00
T1684 Social Engineeringstealth00
T1685.004 Disable or Modify Linux Audit System Logdefense impairment10
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2017-12637SAP NetWeaver T1555 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1552.001 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1007 Mapped
CVE-2021-40449Microsoft Windows T1016 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-41082Microsoft Exchange Server T1567 Mapped
CVE-2023-27532Veeam Backup & Replication T1555 Mapped
CVE-2023-38035Ivanti Sentry T1018 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1555 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1555 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1555 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1552.001 T1552.004 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1018 Mapped
CVE-2025-24054Microsoft Windows T1555 Mapped
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-48927TeleMessage TM SGNL T1555 Mapped
CVE-2025-48928TeleMessage TM SGNL T1555 Mapped
CVE-2025-54309CrushFTP CrushFTP T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1555 Mapped