kevmap

Log sources › m365:defender

m365:defender

Inverted view: what can be detected if this is the log you have. Identity Provider, Office Suite, Windows

4
channels
4
analytics
4
techniques
14
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Activity Log: Command Invocation DC0064 Command Execution AN1087 1
NetworkConnection: high out:in ratio, periodic beacons, protocol mismatch DC0078 Network Traffic Flow AN0927 1
OfficeTelemetry or DLP DC0061 File Modification AN1302 1
ScriptBlockLogging + AMSI DC0029 Script Execution AN0733 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1059.007 JavaScriptexecution2914
T1080 Taint Shared Contentlateral movement00
T1087.004 Cloud Accountdiscovery30
T1132.002 Non-Standard Encodingcommand and control00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2015-5119Adobe Flash Player T1059.007 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 Mapped
CVE-2021-21148Google Chromium V8 T1059.007 Mapped
CVE-2021-21166Google Chromium T1059.007 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059.007 Mapped
CVE-2023-26360Adobe ColdFusion T1059.007 Mapped
CVE-2023-5631Roundcube Webmail T1059.007 Mapped
CVE-2025-34028Commvault Command Center T1059.007 Mapped