kevmap

Log sources › macos:endpointsecurity

macos:endpointsecurity

Inverted view: what can be detected if this is the log you have. macOS

23
channels
35
analytics
35
techniques
152
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
ES_EVENT_MMAP DC0020 Process Modification AN0068 1
ES_EVENT_TYPE_NOTIFY_CONNECT DC0082 Network Connection Creation AN0598 1
ES_EVENT_TYPE_NOTIFY_CREATE: path under /Users/*/(Downloads|Desktop|Library/*/Containers|Library/Group Containers) AND extension in SuspiciousExtensions DC0039 File Creation AN0820 1
ES_EVENT_TYPE_NOTIFY_EXEC DC0032 Process Creation AN0013 AN0057 AN0090 AN0167 AN0256 AN0326 AN0357 AN0601 AN0639 AN0915 AN0921 AN1120 AN1396 AN1409 AN1462 AN1467 16
ES_EVENT_TYPE_NOTIFY_EXEC, ES_EVENT_TYPE_NOTIFY_MMAP DC0034 Process Metadata AN1401 1
ES_EVENT_TYPE_NOTIFY_EXEC: Process execution of "sharing -l", "smbutil view", "mount_smbfs" DC0032 Process Creation AN0515 1
ES_EVENT_TYPE_NOTIFY_EXEC: arguments contain long, non-standard tokens / custom alphabets DC0032 Process Creation AN0929 1
ES_EVENT_TYPE_NOTIFY_KEXTLOAD DC0016 Module Load AN1421 1
ES_EVENT_TYPE_NOTIFY_MMAP DC0020 Process Modification AN0915 AN0921 2
ES_EVENT_TYPE_NOTIFY_OPEN DC0035 Process Access AN0915 1
ES_EVENT_TYPE_NOTIFY_OPEN: Open of .dylib/.so in user-writable locations DC0055 File Access AN0054 1
ES_EVENT_TYPE_NOTIFY_WRITE, targeting .zshrc, .zlogin, .zprofile DC0061 File Modification AN0060 1
es_event_authentication DC0059 File Metadata AN1037 1
es_event_exec DC0032 Process Creation AN0239 1
es_event_file_rename_t or es_event_file_write_t DC0059 File Metadata AN0349 1
es_event_open, es_event_exec DC0055 File Access AN1311 1
exec DC0032 Process Creation AN0023 AN0864 2
exec events DC0032 Process Creation AN1601 1
exec: Exec of ffmpeg, avfoundation-based binaries, or custom signed apps accessing camera DC0032 Process Creation AN0570 1
exec: Process execution context for loaders calling dlopen/dlsym DC0032 Process Creation AN0054 1
open or read syscall to ~/.bash_history DC0055 File Access AN1086 1
open: Process opens AppleCamera/IOUSB device nodes or AVFoundation frameworks DC0055 File Access AN0570 1
write, rename DC0061 File Modification AN1482 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1027.002 Software Packingstealth10
T1027.008 Stripped Payloadsstealth00
T1027.009 Embedded Payloadsstealth20
T1027.010 Command Obfuscationstealth100
T1027.013 Encrypted/Encoded Filestealth00
T1027.014 Polymorphic Codestealth00
T1027.016 Junk Code Insertionstealth00
T1027.017 SVG Smugglingstealth00
T1029 Scheduled Transferexfiltration00
T1030 Data Transfer Size Limitsexfiltration20
T1033 System Owner/User Discoverydiscovery302
T1036 Masqueradingstealth402
T1036.001 Invalid Code Signaturestealth00
T1036.002 Right-to-Left Overridestealth30
T1036.003 Rename Legitimate Utilitiesstealth270
T1036.004 Masquerade Task or Servicestealth30
T1055 Process Injectionstealth, privilege escalation3719
T1068 Exploitation for Privilege Escalationprivilege escalation3169
T1102.003 One-Way Communicationcommand and control20
T1104 Multi-Stage Channelscommand and control00
T1105 Ingress Tool Transfercommand and control8735
T1106 Native APIexecution147
T1114 Email Collectioncollection43
T1125 Video Capturecollection10
T1129 Shared Modulesexecution20
T1132.002 Non-Standard Encodingcommand and control00
T1135 Network Share Discoverydiscovery70
T1195 Supply Chain Compromiseinitial access11
T1195.001 Compromise Software Dependencies and Development Toolsinitial access20
T1195.002 Compromise Software Supply Chaininitial access172
T1195.003 Compromise Hardware Supply Chaininitial access00
T1204.002 Malicious Fileexecution3933
T1546.004 Unix Shell Configuration Modificationprivilege escalation, persistence10
T1547.007 Re-opened Applicationspersistence, privilege escalation00
T1552.003 Shell Historycredential access30

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2007-5659Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-0655Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-2992Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-1862Adobe Acrobat and Reader, Flash Player T1204.002 Mapped
CVE-2009-3953Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-4324Adobe Acrobat and Reader T1204.002 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 Mapped
CVE-2010-1297Adobe Flash Player T1105 T1204.002 Mapped
CVE-2010-2861Adobe ColdFusion T1105 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1204.002 Mapped
CVE-2011-0611Adobe Flash Player T1105 T1204.002 Mapped
CVE-2011-2462Adobe Reader and Acrobat T1204.002 Mapped
CVE-2012-0754Adobe Flash Player T1105 T1204.002 Mapped
CVE-2012-1535Adobe Flash Player T1105 T1204.002 Mapped
CVE-2013-0641Adobe Reader T1105 T1204.002 Mapped
CVE-2014-0496Adobe Reader and Acrobat T1204.002 Mapped
CVE-2014-0546Adobe Reader and Acrobat T1068 Mapped
CVE-2015-3043Adobe Flash Player T1204.002 Mapped
CVE-2015-3113Adobe Flash Player T1204.002 Mapped
CVE-2015-5119Adobe Flash Player T1105 Mapped
CVE-2015-7645Adobe Flash Player T1204.002 Mapped
CVE-2015-8651Adobe Flash Player T1105 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 T1204.002 Mapped
CVE-2016-1019Adobe Flash Player T1105 Mapped
CVE-2016-4117Adobe Flash Player T1105 T1204.002 Mapped
CVE-2017-11292Adobe Flash Player T1105 T1204.002 Mapped
CVE-2018-15982Adobe Flash Player T1105 T1204.002 Mapped
CVE-2018-4878Adobe Flash Player T1204.002 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1204.002 Mapped
CVE-2019-0211Apache HTTP Server T1068 Mapped
CVE-2020-0069MediaTek Multiple Chipsets T1068 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2020-0787Microsoft Windows T1068 Mapped
CVE-2020-1472Microsoft Netlogon T1068 Mapped
CVE-2020-29574Sophos CyberoamOS T1055 Mapped
CVE-2020-8657EyesOfNetwork EyesOfNetwork T1106 Mapped
CVE-2021-21017Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1068 Mapped
CVE-2021-28550Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1068 Mapped
CVE-2021-32030ASUS Routers T1068 Mapped
CVE-2021-33739Microsoft Windows T1068 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1105 Mapped
CVE-2021-36934Microsoft Windows T1068 Mapped
CVE-2021-4034Red Hat Polkit T1068 Mapped
CVE-2021-40449Microsoft Windows T1068 Mapped
CVE-2021-41379Microsoft Windows T1068 Mapped
CVE-2021-44515Zoho Desktop Central T1105 Mapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1195.002 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1068 Mapped
CVE-2022-21919Microsoft Windows T1068 Mapped
CVE-2022-21999Microsoft Windows T1068 Mapped
CVE-2022-22047Microsoft Windows T1068 Mapped
CVE-2022-22718Microsoft Windows T1068 Mapped
CVE-2022-22948VMware vCenter Server T1068 Mapped
CVE-2022-24521Microsoft Windows T1068 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-26904Microsoft Windows T1068 Mapped
CVE-2022-30190Microsoft Windows T1105 T1204.002 Mapped
CVE-2022-34713Microsoft Windows T1204.002 Mapped
CVE-2022-37969Microsoft Windows T1068 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1068 Mapped
CVE-2022-41073Microsoft Windows T1068 Mapped
CVE-2022-41125Microsoft Windows T1068 Mapped
CVE-2022-47966Zoho ManageEngine T1068 Mapped
CVE-2023-1389TP-Link Archer AX21 T1106 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1068 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1068 Mapped
CVE-2023-20867VMware Tools T1105 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1204.002 Mapped
CVE-2023-21674Microsoft Windows T1068 Mapped
CVE-2023-21715Microsoft Office T1204.002 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1033 T1105 Mapped
CVE-2023-26360Adobe ColdFusion T1105 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1204.002 Mapped
CVE-2023-27350PaperCut MF/NG T1105 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1068 Mapped
CVE-2023-28252Microsoft Windows T1068 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1105 Mapped
CVE-2023-29300Adobe ColdFusion T1105 Mapped
CVE-2023-33538TP-Link Multiple Routers T1068 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1055 Mapped
CVE-2023-34362Progress MOVEit Transfer T1105 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1105 Mapped
CVE-2023-36884Microsoft Windows T1204.002 Stale
CVE-2023-38035Ivanti Sentry T1105 Mapped
CVE-2023-38203Adobe ColdFusion T1105 Mapped
CVE-2023-38831RARLAB WinRAR T1105 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1068 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1105 Mapped
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway T1055 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1105 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1068 Mapped
CVE-2024-12987DrayTek Vigor Routers T1068 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1106 Mapped
CVE-2024-23692Rejetto HTTP File Server T1105 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1114 Mapped
CVE-2024-29059Microsoft .NET Framework T1068 Mapped
CVE-2024-30051Microsoft DWM Core Library T1068 Mapped
CVE-2024-37085VMware ESXi T1068 Mapped
CVE-2024-38080Microsoft Windows T1068 T1204.002 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1055 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1055 Mapped
CVE-2024-41710Mitel SIP Phones T1068 Mapped
CVE-2024-41713Mitel MiCollab T1068 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped
CVE-2024-4577PHP Group PHP T1033 T1068 Mapped
CVE-2024-4885Progress WhatsUp Gold T1068 Mapped
CVE-2024-49035Microsoft Partner Center T1068 T1195 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1105 T1195.002 Mapped
CVE-2024-50603Aviatrix Controllers T1055 Mapped
CVE-2024-53104Linux Kernel T1068 Mapped
CVE-2024-53197Linux Kernel T1068 Mapped
CVE-2024-54085AMI MegaRAC SPx T1068 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1068 Mapped
CVE-2024-56145Craft CMS Craft CMS T1055 Mapped
CVE-2024-58136Yiiframework Yii T1055 Mapped
CVE-2024-6047GeoVision Multiple Devices T1055 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1055 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1068 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1055 Mapped
CVE-2025-0994Trimble Cityworks T1068 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1055 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1068 Mapped
CVE-2025-20281Cisco Identity Services Engine T1106 Mapped
CVE-2025-20337Cisco Identity Services Engine T1106 Mapped
CVE-2025-21333Microsoft Windows T1068 Mapped
CVE-2025-21334Microsoft Windows T1068 Mapped
CVE-2025-21335Microsoft Windows T1068 Mapped
CVE-2025-21391Microsoft Windows T1068 Mapped
CVE-2025-21418Microsoft Windows T1055 T1068 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1055 Mapped
CVE-2025-21590Juniper Junos OS T1068 Mapped
CVE-2025-22224VMware ESXi and Workstation T1055 Mapped
CVE-2025-22225VMware ESXi T1068 Mapped
CVE-2025-24085Apple Multiple Products T1068 Mapped
CVE-2025-24993Microsoft Windows T1055 T1068 Mapped
CVE-2025-25181Advantive VeraCore T1055 T1068 Mapped
CVE-2025-25257Fortinet FortiWeb T1055 T1068 Mapped
CVE-2025-27363FreeType FreeType T1204.002 Mapped
CVE-2025-30400Microsoft Windows T1068 Mapped
CVE-2025-31200Apple Multiple Products T1105 T1106 Stale
CVE-2025-31201Apple Multiple Products T1105 T1106 Stale
CVE-2025-31324SAP NetWeaver T1055 Mapped
CVE-2025-32701Microsoft Windows T1068 Mapped
CVE-2025-32706Microsoft Windows T1068 Mapped
CVE-2025-32709Microsoft Windows T1068 Mapped
CVE-2025-43200Apple Multiple Products T1105 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1068 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1068 Mapped
CVE-2025-54309CrushFTP CrushFTP T1068 Mapped