Log sources › containerd:runtime
containerd:runtime
Inverted view: what can be detected if this is the log you have. Containers
5
channels
5
analytics
5
techniques
79
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/var/log/containers/*.log |
DC0032 Process Creation | AN0358 | 1 |
CRI CreateContainer/StartContainer with privileged=true OR added capabilities OR host* namespaces |
DC0077 Container Start | AN0693 | 1 |
container-level outbound traffic events |
DC0078 Network Traffic Flow | AN1060 | 1 |
e.g., containerd, Docker events |
DC0091 Container Enumeration | AN1422 | 1 |
file change monitoring within /etc/cron.*, /tmp, or mounted volumes |
DC0061 File Modification | AN0261 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036 Masquerading | stealth | 40 | 2 |
| T1046 Network Service Discovery | discovery | 20 | 7 |
| T1053 Scheduled Task/Job | execution, persistence, privilege escalation | 12 | 2 |
| T1068 Exploitation for Privilege Escalation | privilege escalation | 31 | 69 |
| T1610 Deploy Container | execution | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2014-0546 | Adobe Reader and Acrobat | T1068 | Mapped |
| CVE-2019-0211 | Apache HTTP Server | T1068 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1046 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1046 | Mapped |
| CVE-2020-0069 | MediaTek Multiple Chipsets | T1068 | Mapped |
| CVE-2020-0787 | Microsoft Windows | T1068 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1068 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 | Mapped |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | T1068 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1068 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1068 | Mapped |
| CVE-2021-33739 | Microsoft Windows | T1068 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1068 | Mapped |
| CVE-2021-4034 | Red Hat Polkit | T1068 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1068 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1068 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1068 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1068 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1068 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1068 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1068 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1068 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1068 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1046 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1068 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1068 | Mapped |
| CVE-2023-33538 | TP-Link Multiple Routers | T1068 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1046 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1053 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1068 | Mapped |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | T1068 | Mapped |
| CVE-2024-12987 | DrayTek Vigor Routers | T1068 | Mapped |
| CVE-2024-29059 | Microsoft .NET Framework | T1068 | Mapped |
| CVE-2024-30051 | Microsoft DWM Core Library | T1068 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1068 | Mapped |
| CVE-2024-38080 | Microsoft Windows | T1068 | Mapped |
| CVE-2024-41710 | Mitel SIP Phones | T1068 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1068 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1053 T1068 | Mapped |
| CVE-2024-4885 | Progress WhatsUp Gold | T1068 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1068 | Mapped |
| CVE-2024-53104 | Linux Kernel | T1068 | Mapped |
| CVE-2024-53197 | Linux Kernel | T1068 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1068 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1068 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1068 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1046 | Mapped |
| CVE-2025-0994 | Trimble Cityworks | T1068 | Mapped |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | T1068 | Mapped |
| CVE-2025-21333 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-21334 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-21335 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-21590 | Juniper Junos OS | T1068 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1068 | Mapped |
| CVE-2025-24085 | Apple Multiple Products | T1068 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1068 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1068 | Mapped |
| CVE-2025-30400 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1046 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1068 | Mapped |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | T1068 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1068 | Mapped |