kevmap

Log sources › auditd:PATH

auditd:PATH

Inverted view: what can be detected if this is the log you have. Linux

14
channels
16
analytics
16
techniques
12
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/etc/passwd or /etc/group file write DC0061 File Modification AN0266 1
Creation of files with extensions .sql, .csv, .sqlite, especially in user directories DC0039 File Creation AN0676 1
New .py/.js/.sh files written to ~/.local/, ~/.cache/, or /tmp/ within 5 min of package install DC0039 File Creation AN0698 1
PATH DC0055 File Access
DC0059 File Metadata
AN0312 AN0847 AN1041 3
Read access to known backup software configuration files (e.g., /etc/rsnapshot.conf, /opt/veeam/config.ini) DC0055 File Access AN0241 1
WRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirs DC0039 File Creation AN1367 1
creation of .so files in non-standard directories (e.g., /tmp, /home/*) DC0039 File Creation AN1209 1
file path matches exclusion directories DC0059 File Metadata AN0140 1
file read DC0055 File Access AN1281 1
mount target path within /proc/* DC0039 File Creation AN1196 1
odification of ~/.ssh/authorized_keys or credential files DC0061 File Modification AN2037 1
open: Access to sensitive log files (/var/log/auth.log, /var/log/secure, /var/log/syslog) DC0055 File Access AN0706 1
write or create events on *.pth, sitecustomize.py, usercustomize.py in site-packages or dist-packages DC0061 File Modification AN0713 1
write: File modifications to /etc/systemd/sleep.conf or related power configuration files DC0061 File Modification AN1175 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1016.002 Wi-Fi Discoverydiscovery00
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1083 File and Directory Discoverydiscovery245
T1087.001 Local Accountdiscovery131
T1098 Account Manipulationpersistence, privilege escalation342
T1204.005 Malicious Libraryexecution00
T1213.006 Databasescollection00
T1219 Remote Access Toolscommand and control61
T1518.002 Backup Software Discoverydiscovery00
T1546.018 Python Startup Hookspersistence, privilege escalation00
T1564.012 File/Path Exclusionsstealth00
T1564.013 Bind Mountsstealth00
T1574.006 Dynamic Linker Hijackingstealth, execution20
T1653 Power Settingspersistence11
T1654 Log Enumerationdiscovery00
T1684 Social Engineeringstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2012-0767Adobe Flash Player T1098 Mapped
CVE-2017-12637SAP NetWeaver T1083 Mapped
CVE-2018-4878Adobe Flash Player T1219 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1083 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1083 Mapped
CVE-2021-32030ASUS Routers T1098 Mapped
CVE-2022-41328Fortinet FortiOS T1037 Mapped
CVE-2023-22952SugarCRM Multiple Products T1083 Stale
CVE-2023-27532Veeam Backup & Replication T1087.001 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1653 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-53704SonicWall SonicOS T1083 Mapped