kevmap

Log sources › macos:keychain

macos:keychain

Inverted view: what can be detected if this is the log you have. macOS

2
channels
2
analytics
2
techniques
18
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Access to Keychain DB or system.keychain DC0055 File Access AN0650 1
~/Library/Keychains, /Library/Keychains DC0055 File Access AN0673 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1003 OS Credential Dumpingcredential access3718
T1649 Steal or Forge Authentication Certificatescredential access110

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2019-0604Microsoft SharePoint T1003 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1003 Mapped
CVE-2019-13608Citrix StoreFront Server T1003 Mapped
CVE-2020-5902F5 BIG-IP T1003 Stale
CVE-2021-22893Ivanti Pulse Connect Secure T1003 Mapped
CVE-2021-40539Zoho ManageEngine T1003 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1003 Mapped
CVE-2021-44515Zoho Desktop Central T1003 Mapped
CVE-2023-28252Microsoft Windows T1003 Mapped
CVE-2024-4577PHP Group PHP T1003 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1003 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1003 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1003 Mapped
CVE-2025-21333Microsoft Windows T1003 Mapped
CVE-2025-21334Microsoft Windows T1003 Mapped
CVE-2025-21335Microsoft Windows T1003 Mapped
CVE-2025-32709Microsoft Windows T1003 Mapped
CVE-2025-32756Fortinet Multiple Products T1003 Mapped