kevmap

Log sources › kubernetes:audit

kubernetes:audit

Inverted view: what can be detected if this is the log you have. Containers, Linux

11
channels
11
analytics
10
techniques
72
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Failed login DC0002 User Account Authentication AN1341 1
GET or LIST requests to /var/run/secrets/kubernetes.io/serviceaccount/ followed by access to the Kubernetes API server DC0055 File Access AN1423 1
Shell process (e.g., /bin/sh, /bin/bash) spawned in a container without an interactive session attached (i.e., automation anomaly) DC0064 Command Execution AN0233 1
Unauthorized container creation or kubelet exec logs DC0088 Logon Session Metadata AN1007 1
authentication.k8s.io DC0002 User Account Authentication AN1547 1
create DC0019 Pod Creation
DC0060 Service Creation
AN1304 1
create or update events for RoleBinding or ClusterRoleBinding objects DC0010 User Account Modification AN1579 1
create: Pod/Container created with image tag 'latest' or mutable tag; imagePullPolicy=Always; noDigest=true DC0072 Container Creation AN0691 1
kubectl delete or patch of security pods/admission controllers DC0041 Service Metadata AN1373 1
process execution involving curl, grep, or awk on secrets DC0064 Command Execution AN0859 1
seccomp or AppArmor profile changes DC0041 Service Metadata AN0889 0

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1059.013 Container CLI/APIexecution00
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1098.006 Additional Container Cluster Rolespersistence, privilege escalation00
T1110.003 Password Sprayingcredential access00
T1133 External Remote Servicespersistence, initial access2025
T1204.003 Malicious Imageexecution00
T1528 Steal Application Access Tokencredential access141
T1543.005 Container Servicepersistence, privilege escalation00
T1552.001 Credentials In Filescredential access243
T1685 Disable or Modify Toolsdefense impairment1640

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1133 Mapped
CVE-2018-4939Adobe ColdFusion T1133 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1133 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1133 T1552.001 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1078 Mapped
CVE-2019-13608Citrix StoreFront Server T1078 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1133 Mapped
CVE-2019-5591Fortinet FortiOS T1133 Mapped
CVE-2020-1472Microsoft Netlogon T1133 Mapped
CVE-2020-25506D-Link DNS-320 Device T1133 Mapped
CVE-2020-5902F5 BIG-IP T1133 Stale
CVE-2020-8515DrayTek Multiple Vigor Routers T1133 Mapped
CVE-2021-1497Cisco HyperFlex HX T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1133 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1078 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1133 Mapped
CVE-2021-26855Microsoft Exchange Server T1133 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 Mapped
CVE-2021-36934Microsoft Windows T1078 Mapped
CVE-2021-41379Microsoft Windows T1078 Mapped
CVE-2021-42321Microsoft Exchange T1078 Mapped
CVE-2022-1040Sophos Firewall T1078 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1133 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 Mapped
CVE-2022-21919Microsoft Windows T1078 Mapped
CVE-2022-21999Microsoft Windows T1078 Mapped
CVE-2022-22047Microsoft Windows T1078 Mapped
CVE-2022-22718Microsoft Windows T1078 Mapped
CVE-2022-22948VMware vCenter Server T1078 Mapped
CVE-2022-23131Zabbix Frontend T1078 Mapped
CVE-2022-24521Microsoft Windows T1078 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26500Veeam Backup & Replication T1078 Mapped
CVE-2022-26904Microsoft Windows T1078 Mapped
CVE-2022-37969Microsoft Windows T1078 Mapped
CVE-2022-41073Microsoft Windows T1078 Mapped
CVE-2022-41082Microsoft Exchange Server T1078 Mapped
CVE-2022-41125Microsoft Windows T1078 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1078 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1078 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 T1133 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1078 Mapped
CVE-2023-20867VMware Tools T1078 Mapped
CVE-2023-21674Microsoft Windows T1078 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1078 Mapped
CVE-2023-22952SugarCRM Multiple Products T1078 Stale
CVE-2023-23397Microsoft Office T1078 Mapped
CVE-2023-27524Apache Superset T1078 Mapped
CVE-2023-27532Veeam Backup & Replication T1133 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1078 Mapped
CVE-2023-28252Microsoft Windows T1078 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1078 T1133 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1078 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 Mapped
CVE-2023-48365Qlik Sense T1133 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1078 Mapped
CVE-2024-20399Cisco NX-OS T1078 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 Mapped
CVE-2024-37085VMware ESXi T1078 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped
CVE-2024-45195Apache OFBiz T1133 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1078 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1552.001 Mapped
CVE-2024-57968Advantive VeraCore T1078 Mapped
CVE-2025-24016Wazuh Wazuh Server T1078 Mapped
CVE-2025-31161CrushFTP CrushFTP T1078 Mapped
CVE-2025-32756Fortinet Multiple Products T1133 Mapped