Log sources › ebpf:syscalls
ebpf:syscalls
Inverted view: what can be detected if this is the log you have. Containers, IaaS, Linux
9
channels
8
analytics
8
techniques
17
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Process within container accesses link-local address 169.254.169.254 |
DC0085 Network Traffic Content | AN0001 | 1 |
Unexpected container volume unmount + file deletion |
DC0059 File Metadata | AN0523 | 1 |
container_file_activity |
DC0055 File Access | AN0600 | 1 |
execve |
DC0032 Process Creation | AN1060 | 1 |
file_write |
DC0061 File Modification | AN0358 | 1 |
open/read on secret mount paths |
DC0055 File Access | AN0859 | 1 |
process execution or network connect from just-created container PID namespace |
DC0032 Process Creation | AN0693 | 1 |
socket connect |
DC0082 Network Connection Creation | AN1060 | 1 |
useradd or /etc/passwd modified inside container |
DC0064 Command Execution | AN1239 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1027.009 Embedded Payloads | stealth | 2 | 0 |
| T1036 Masquerading | stealth | 40 | 2 |
| T1046 Network Service Discovery | discovery | 20 | 7 |
| T1070 Indicator Removal | stealth | 20 | 3 |
| T1136.001 Local Account | persistence | 18 | 2 |
| T1552.001 Credentials In Files | credential access | 24 | 3 |
| T1552.005 Cloud Instance Metadata API | credential access | 0 | 0 |
| T1610 Deploy Container | execution | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1552.001 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1046 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1046 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1136.001 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1136.001 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1046 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1046 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1552.001 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1046 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1046 | Mapped |