kevmap

Log sources › ebpf:syscalls

ebpf:syscalls

Inverted view: what can be detected if this is the log you have. Containers, IaaS, Linux

9
channels
8
analytics
8
techniques
17
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Process within container accesses link-local address 169.254.169.254 DC0085 Network Traffic Content AN0001 1
Unexpected container volume unmount + file deletion DC0059 File Metadata AN0523 1
container_file_activity DC0055 File Access AN0600 1
execve DC0032 Process Creation AN1060 1
file_write DC0061 File Modification AN0358 1
open/read on secret mount paths DC0055 File Access AN0859 1
process execution or network connect from just-created container PID namespace DC0032 Process Creation AN0693 1
socket connect DC0082 Network Connection Creation AN1060 1
useradd or /etc/passwd modified inside container DC0064 Command Execution AN1239 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1027.009 Embedded Payloadsstealth20
T1036 Masqueradingstealth402
T1046 Network Service Discoverydiscovery207
T1070 Indicator Removalstealth203
T1136.001 Local Accountpersistence182
T1552.001 Credentials In Filescredential access243
T1552.005 Cloud Instance Metadata APIcredential access00
T1610 Deploy Containerexecution00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2019-11510Ivanti Pulse Connect Secure T1552.001 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1046 Mapped
CVE-2019-13608Citrix StoreFront Server T1046 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 Mapped
CVE-2022-21999Microsoft Windows T1136.001 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2022-47966Zoho ManageEngine T1136.001 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped
CVE-2023-26360Adobe ColdFusion T1046 Mapped
CVE-2023-38035Ivanti Sentry T1046 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1552.001 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1046 Mapped
CVE-2025-32756Fortinet Multiple Products T1046 Mapped