Log sources › macos:osquery
macos:osquery
Inverted view: what can be detected if this is the log you have. macOS
59
channels
94
analytics
94
techniques
140
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
CALCULATE: Integrity validation of transmitted data via hash checks |
DC0021 OS API Execution | AN0704 | 1 |
CALCULATE: Mismatch in file integrity of critical macOS applications |
DC0061 File Modification | AN1099 | 1 |
CONNECT: Long-lived connections from remote-control parents to external IPs/domains |
DC0082 Network Connection Creation | AN1368 | 1 |
CREATE, DELETE, WRITE: Stored data manipulation attempts by unauthorized processes |
DC0040 File Deletion | AN0557 | 1 |
CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations |
DC0039 File Creation | AN1368 | 1 |
CREATE/MODIFY: Modification of app.asar inside .app bundle |
DC0039 File Creation | AN0073 | 1 |
Changes to LSFileQuarantineEnabled field in Info.plist |
DC0061 File Modification | AN0800 | 1 |
Execution of flooding tools or compiled packet generators |
DC0032 Process Creation | AN1014 | 1 |
Execution of non-standard binaries accessing Kerberos APIs |
DC0032 Process Creation | AN0070 | 1 |
File modifications in ~/Library/Preferences/ |
DC0061 File Modification | AN0522 | 1 |
Interpreter exec with suspicious arguments as above |
DC0064 Command Execution | AN0964 | 1 |
Invocation of osascript or dylib injection |
DC0032 Process Creation | AN0650 | 1 |
Memory Mappings |
DC0020 Process Modification | AN0391 | 1 |
Modifications to /var/db/SystemPolicyConfiguration/KextPolicy or kext_policy table |
DC0061 File Modification | AN1244 | 1 |
New kext entries not signed by Apple or outside standard identifier prefix |
DC0031 Kernel Module Load | AN1244 | 1 |
None |
DC0055 File Access DC0082 Network Connection Creation |
AN1533 | 1 |
Process Context |
DC0034 Process Metadata | AN0097 | 1 |
Process Events and Launch Daemons |
DC0060 Service Creation | AN0206 | 1 |
Process Execution + Hash |
DC0034 Process Metadata | AN1296 | 1 |
Processes executing kextload, spctl, or modifying kernel extension directories |
DC0032 Process Creation | AN1244 | 1 |
Rapid spawning of resource-heavy applications (e.g., Preview, Safari, Office) |
DC0032 Process Creation | AN1167 | 1 |
Unsigned or ad-hoc signed process executions in user contexts |
DC0032 Process Creation | AN1248 | 1 |
code_signing, file_metadata |
DC0059 File Metadata | AN0057 | 1 |
curl, python scripts, rsync with internal share URLs |
DC0032 Process Creation | AN1163 | 1 |
detection of new launch agents with suspicious paths or unsigned binaries |
DC0060 Service Creation | AN1208 | 1 |
exec |
DC0032 Process Creation | AN0799 AN1316 | 2 |
exec: Unexpected execution of osascript or AppleScript targeting sensitive apps |
DC0029 Script Execution | AN1359 | 1 |
execution of trusted tools interacting with external endpoints |
DC0082 Network Connection Creation | AN0228 | 1 |
execve |
DC0032 Process Creation | AN0121 AN1563 | 2 |
execve: Processes unexpectedly invoking Keychain or authentication APIs |
DC0032 Process Creation | AN0495 | 1 |
execve: Unsigned or unnotarized processes launched with high privileges |
DC0032 Process Creation | AN1635 | 1 |
file_events |
DC0039 File Creation DC0040 File Deletion DC0055 File Access DC0059 File Metadata DC0061 File Modification |
AN0115 AN0135 AN0333 AN0344 AN0369 AN0542 AN0739 AN1066 AN1218 AN1383 AN1585 AN1628 | 12 |
interface_details |
DC0018 Host Status | AN0214 | 1 |
launch_daemons |
DC0060 Service Creation | AN1063 | 1 |
launchd |
DC0041 Service Metadata | AN0313 | 1 |
launchd + process_events |
DC0064 Command Execution | AN1082 | 1 |
launchd or network_events |
DC0082 Network Connection Creation | AN0924 | 1 |
launchd or process_events |
DC0032 Process Creation | AN0284 | 1 |
launchd, processes |
DC0032 Process Creation | AN1482 | 1 |
launchd_jobs |
DC0001 Scheduled Job Creation | AN0260 | 1 |
mach_o_info, file_metadata |
DC0059 File Metadata | AN0601 | 1 |
open, execve: Unexpected processes accessing or modifying critical files |
DC0021 OS API Execution | AN0164 | 1 |
parent_name in ('sshd','httpd','screensharingd') spawning shells or scripting runtimes. |
DC0032 Process Creation | AN0330 | 1 |
process reading browser configuration paths |
DC0032 Process Creation | AN0039 | 1 |
process_events |
DC0032 Process Creation | AN0032 AN0173 AN0210 AN0214 AN0273 AN0333 AN0369 AN0425 AN0506 AN0566 AN0618 AN0653 AN0734 AN0752 AN0874 AN0905 AN0945 AN0990 AN1059 AN1327 AN1412 AN1415 AN1442 AN1639 | 24 |
process_events + launchd |
DC0082 Network Connection Creation | AN1022 | 1 |
process_events OR launchd |
DC0032 Process Creation | AN0245 | 1 |
process_events where path like '%tcpdump%' |
DC0032 Process Creation | AN0877 | 1 |
process_events, socket_events |
DC0082 Network Connection Creation | AN1191 | 1 |
process_events/socket_events |
DC0082 Network Connection Creation | AN0160 | 1 |
process_open |
DC0035 Process Access | AN0289 | 1 |
process_termination: Unexpected termination of processes tied to vulnerable or high-value services |
DC0033 Process Termination | AN0047 | 1 |
query: Enumeration of root certificates showing unexpected additions |
DC0061 File Modification | AN0155 | 1 |
query: Historical list of associated SSIDs compared against baseline |
DC0078 Network Traffic Flow | AN1478 | 1 |
query: process_events, launchd, and tcc.db access |
DC0032 Process Creation | AN0689 | 1 |
socket_events |
DC0078 Network Traffic Flow | AN0004 AN0077 AN0381 AN0425 AN0990 AN1171 AN1227 AN1391 AN1415 | 9 |
unexpected memory inspection |
DC0035 Process Access | AN1643 | 1 |
usb_devices |
DC0054 Drive Access | AN1355 | 1 |
write |
DC0061 File Modification | AN1251 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-4324 | Adobe Acrobat and Reader | T1071.001 | Mapped |
| CVE-2010-2883 | Adobe Acrobat and Reader | T1027 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 | Mapped |
| CVE-2013-3346 | Adobe Reader and Acrobat | T1059.007 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1071.001 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1059.007 T1071.001 T1203 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1041 T1219 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1203 | Mapped |
| CVE-2018-4990 | Adobe Acrobat and Reader | T1059.007 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1003 T1041 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1003 T1046 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1003 T1046 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1007 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 | Mapped |
| CVE-2020-12812 | Fortinet FortiOS | T1556 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1217 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1003 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1556 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1059.007 T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1059.007 T1203 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1003 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1059.007 T1203 | Mapped |
| CVE-2021-31207 | Microsoft Exchange Server | T1565 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1071.001 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1203 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1027 T1071.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1003 T1027 T1218 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1003 T1027 T1218 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1003 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 T1071 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1211 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1212 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1059.007 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1203 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1027 T1213 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1059.007 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 T1203 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 T1049 T1565.001 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1071.001 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1203 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1210 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 T1070 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059.007 | Mapped |
| CVE-2023-23397 | Microsoft Office | T1203 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1046 T1059.007 T1071.001 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1003 T1021 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1213 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1203 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1018 T1046 T1071.001 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1041 T1053 T1059.004 T1204 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 T1059.004 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1071.002 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 T1059.007 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1203 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1203 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 T1059.004 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1056 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1203 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1003 T1041 T1053 T1071.001 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1003 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1195 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1071.001 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1011 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1203 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1011 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1212 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1210 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1041 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1003 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1565.001 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1003 T1018 T1046 | Mapped |
| CVE-2025-21333 | Microsoft Windows | T1003 | Mapped |
| CVE-2025-21334 | Microsoft Windows | T1003 | Mapped |
| CVE-2025-21335 | Microsoft Windows | T1003 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1203 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1203 T1204 T1565 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1203 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1203 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-3248 | Langflow Langflow | T1203 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1003 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1003 T1041 T1046 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 T1056.001 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1059.007 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1203 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1203 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1203 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1212 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1203 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1203 | Mapped |