kevmap

Log sources › fs:fileevents

fs:fileevents

Inverted view: what can be detected if this is the log you have. Linux, macOS

6
channels
7
analytics
7
techniques
4
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/Library/LaunchDaemons/*.plist, ~/Library/LaunchAgents/*.plist DC0005 Scheduled Job Metadata AN0326 1
/var/log/install.log DC0059 File Metadata
DC0061 File Modification
AN0090 AN0357 2
/var/log/quarantine.log DC0061 File Modification AN0013 1
File system access events with kFSEventStreamEventFlagItemRemoved, kFSEventStreamEventFlagItemRenamed flags for environmental artifact collection (/System/Library, /usr/sbin, plist files) DC0055 File Access AN1553 1
creat DC0039 File Creation AN0253 1
create/write/rename in user-writable paths DC0039 File Creation AN1316 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2023-38831RARLAB WinRAR T1204 Mapped
CVE-2025-24993Microsoft Windows T1204 Mapped