Log sources › AWS:CloudWatch
AWS:CloudWatch
Inverted view: what can be detected if this is the log you have. IaaS
9
channels
9
analytics
9
techniques
30
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Elevated 5xx response rates in application logs or gateway layer |
DC0038 Application Log Content | AN1168 | 1 |
NetworkOut spike beyond baseline |
DC0018 Host Status | AN0972 | 1 |
Repeated crash pattern within container or instance logs |
DC0038 Application Log Content | AN0853 | 1 |
StatusCheckFailed or StatusCheckFailed_System for burstable instances (t2/t3) |
DC0018 Host Status | AN0587 | 1 |
Sudden spike in network output without a corresponding inbound request ratio |
DC0018 Host Status | AN1143 | 1 |
Sustained EC2 CPU usage above normal baseline |
DC0018 Host Status | AN0744 | 1 |
Sustained spike in CPU usage on EC2 instance with web service role |
DC0018 Host Status | AN0492 | 1 |
Unusual CPU burst or metric anomalies |
DC0018 Host Status | AN1493 | 1 |
unexpected IAM user or role assuming privileges for instance/snapshot operations |
DC0070 Cloud Service Metadata | AN0861 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1496 Resource Hijacking | impact | 13 | 19 |
| T1496.001 Compute Hijacking | impact | 0 | 0 |
| T1498.001 Direct Network Flood | impact | 0 | 1 |
| T1498.002 Reflection Amplification | impact | 0 | 0 |
| T1499 Endpoint Denial of Service | impact | 3 | 7 |
| T1499.002 Service Exhaustion Flood | impact | 0 | 2 |
| T1499.003 Application Exhaustion Flood | impact | 0 | 0 |
| T1499.004 Application or System Exploitation | impact | 3 | 2 |
| T1578 Modify Cloud Compute Infrastructure | defense impairment | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2015-3043 | Adobe Flash Player | T1499.004 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1496 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1496 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1496 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1496 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1496 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1496 T1499 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1496 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1499.002 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1499.002 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1496 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1496 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1499 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1496 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1496 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1499 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1496 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1498.001 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1499 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1499.004 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1499 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |