kevmap

Log sources › journald:package

journald:package

Inverted view: what can be detected if this is the log you have. Linux

3
channels
3
analytics
3
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
dpkg/apt install, remove, upgrade events DC0059 File Metadata AN1481 1
dpkg/apt or yum/dnf transaction logs (install/update of build tools) DC0059 File Metadata AN0022 1
dpkg/apt/yum/dnf transaction logs; vendor updaters in systemd journals DC0059 File Metadata AN0863 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1195.002 Mapped
CVE-2024-49035Microsoft Partner Center T1195 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1195.002 Mapped