Log sources › linux:Sysmon
linux:Sysmon
Inverted view: what can be detected if this is the log you have. Linux
5
channels
11
analytics
11
techniques
32
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
EventCode=1 |
DC0032 Process Creation | AN0120 AN0620 AN0847 AN1562 AN1613 AN1631 | 6 |
EventCode=3, 22 |
DC0082 Network Connection Creation | AN0238 AN1161 | 2 |
EventCode=7 |
DC0016 Module Load | AN0473 | 1 |
New files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetch |
DC0039 File Creation | AN0499 | 1 |
process creation events linked to container namespaces executing host-level binaries |
DC0032 Process Creation | AN0613 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1003.007 Proc Filesystem | credential access | 0 | 0 |
| T1027.013 Encrypted/Encoded File | stealth | 0 | 0 |
| T1087 Account Discovery | discovery | 16 | 6 |
| T1087.001 Local Account | discovery | 13 | 1 |
| T1123 Audio Capture | collection | 6 | 0 |
| T1189 Drive-by Compromise | initial access | 3 | 21 |
| T1213 Data from Information Repositories | collection | 7 | 2 |
| T1505.002 Transport Agent | persistence | 3 | 0 |
| T1611 Escape to Host | privilege escalation | 2 | 3 |
| T1614 System Location Discovery | discovery | 0 | 0 |
| T1614.001 System Language Discovery | discovery | 2 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1087 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1213 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1087 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 T1087.001 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1213 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1611 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1611 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1611 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |