kevmap

Log sources › fs:fsusage

fs:fsusage

Inverted view: what can be detected if this is the log you have. macOS

30
channels
31
analytics
31
techniques
74
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Detached process execution with no associated parent DC0021 OS API Execution AN1224 1
Disk Activity Tracing DC0055 File Access AN0618 1
File Access Monitor DC0055 File Access AN0391 1
File IO DC0039 File Creation AN0621 1
Filesystem Access Logging DC0061 File Modification AN1322 1
Filesystem Call Monitoring DC0055 File Access AN1042 1
access to BPF devices or interface IOCTLs DC0064 Command Execution AN0877 1
binary execution of security_authtrampoline DC0032 Process Creation AN0977 1
create: Attachment file creation in ~/Library/Mail directories DC0039 File Creation AN1011 1
disk activity on /Library/LaunchAgents or LaunchDaemons DC0039 File Creation AN0260 1
file DC0055 File Access AN0313 1
file access to /usr/lib/cron/at and job execution path DC0061 File Modification AN0945 1
file access to /usr/lib/cron/tabs/ and cron output files DC0061 File Modification AN0806 1
file activity DC0039 File Creation AN0659 1
file open for known browser cookie paths DC0055 File Access AN1404 1
file open/write DC0039 File Creation AN0784 AN0921 2
file reads/writes from /Volumes/ DC0055 File Access AN1412 1
file system activity monitor DC0064 Command Execution AN0344 1
file write DC0039 File Creation AN1530 1
file write to launchd plist paths DC0061 File Modification AN1577 1
filesystem activity DC0055 File Access AN0813 1
filesystem monitoring of exec/open DC0059 File Metadata AN0985 1
modification of existing LaunchAgents plist DC0061 File Modification AN1208 1
open/read/mount operations DC0054 Drive Access AN1147 1
open/write/exec calls DC0039 File Creation AN0249 1
read/write DC0055 File Access AN1072 1
truncate, unlink, write DC0061 File Modification AN1439 1
unlink, fs_delete DC0040 File Deletion AN0522 1
unlink, write DC0061 File Modification AN0394 AN0468 2
write or chmod to ~/Library/LaunchAgents/*.plist DC0039 File Creation AN1208 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1005 Data from Local Systemcollection1446
T1025 Data from Removable Mediacollection00
T1027.001 Binary Paddingstealth30
T1027.014 Polymorphic Codestealth00
T1027.015 Compressionstealth00
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1036.006 Space after Filenamestealth10
T1036.009 Break Process Treesstealth00
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1037.004 RC Scriptspersistence, privilege escalation00
T1039 Data from Network Shared Drivecollection20
T1040 Network Sniffingcredential access, discovery92
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.002 Atexecution, persistence, privilege escalation80
T1053.003 Cronexecution, persistence, privilege escalation60
T1056.003 Web Portal Capturecollection, credential access00
T1056.004 Credential API Hookingcollection, credential access00
T1070 Indicator Removalstealth203
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1083 File and Directory Discoverydiscovery245
T1092 Communication Through Removable Mediacommand and control00
T1123 Audio Capturecollection60
T1539 Steal Web Session Cookiecredential access20
T1543 Create or Modify System Processpersistence, privilege escalation99
T1543.001 Launch Agentpersistence, privilege escalation20
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1667 Email Bombingimpact00
T1685.006 Clear Linux or Mac System Logsdefense impairment40

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2013-0629Adobe ColdFusion T1005 Mapped
CVE-2017-11292Adobe Flash Player T1005 Mapped
CVE-2017-12637SAP NetWeaver T1083 Mapped
CVE-2017-5638Apache Struts T1005 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1083 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1005 Mapped
CVE-2019-13608Citrix StoreFront Server T1005 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1083 Mapped
CVE-2019-5591Fortinet FortiOS T1005 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 Mapped
CVE-2020-5902F5 BIG-IP T1005 T1070.004 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 Mapped
CVE-2021-27101Accellion FTA T1005 Mapped
CVE-2021-27102Accellion FTA T1005 Mapped
CVE-2021-27103Accellion FTA T1005 Mapped
CVE-2021-27104Accellion FTA T1005 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 Mapped
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2021-40539Zoho ManageEngine T1070.004 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1070.004 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 T1543 Mapped
CVE-2022-1040Sophos Firewall T1040 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-23131Zabbix Frontend T1548 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2022-41328Fortinet FortiOS T1037 Mapped
CVE-2023-0386Linux Kernel T1543 Stale
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped
CVE-2023-22952SugarCRM Multiple Products T1070.004 T1083 Stale
CVE-2023-26360Adobe ColdFusion T1036.005 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 Mapped
CVE-2023-36884Microsoft Windows T1005 Stale
CVE-2023-38831RARLAB WinRAR T1005 T1053 Mapped
CVE-2023-38950ZKTeco BioTime T1005 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1543 T1548 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1005 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 Mapped
CVE-2024-38475Apache HTTP Server T1005 Mapped
CVE-2024-41713Mitel MiCollab T1005 Mapped
CVE-2024-4577PHP Group PHP T1053 T1543 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1005 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 Mapped
CVE-2024-50302Linux Kernel T1005 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 Mapped
CVE-2024-53150Linux Kernel T1005 Mapped
CVE-2024-53704SonicWall SonicOS T1083 Mapped
CVE-2024-55550Mitel MiCollab T1005 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 Mapped
CVE-2025-21418Microsoft Windows T1005 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 Mapped
CVE-2025-24991Microsoft Windows T1005 Mapped
CVE-2025-2783Google Chromium Mojo T1548 Mapped
CVE-2025-32701Microsoft Windows T1543 Mapped
CVE-2025-32706Microsoft Windows T1543 Mapped
CVE-2025-32709Microsoft Windows T1543 Mapped
CVE-2025-32756Fortinet Multiple Products T1070.004 Mapped
CVE-2025-33053Microsoft Windows T1543 Mapped
CVE-2025-43200Apple Multiple Products T1005 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1543 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 Mapped