kevmap

Log sources › Network Traffic

Network Traffic

Inverted view: what can be detected if this is the log you have. PRE, Windows

1
channels
15
analytics
15
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
None DC0078 Network Traffic Flow
DC0085 Network Traffic Content
AN0872 AN1946 AN1949 AN1953 AN1955 AN1962 AN1973 AN1983 AN1997 AN1999 AN2000 AN2002 AN2005 AN2008 AN2010 15

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1027.006 HTML Smugglingstealth00
T1585 Establish Accountsresource development00
T1585.001 Social Media Accountsresource development00
T1586 Compromise Accountsresource development20
T1586.001 Social Media Accountsresource development00
T1589 Gather Victim Identity Informationreconnaissance20
T1589.002 Email Addressesreconnaissance10
T1595 Active Scanningreconnaissance31
T1595.001 Scanning IP Blocksreconnaissance10
T1595.002 Vulnerability Scanningreconnaissance10
T1595.003 Wordlist Scanningreconnaissance00
T1598 Phishing for Informationreconnaissance00
T1598.001 Spearphishing Servicereconnaissance00
T1598.002 Spearphishing Attachmentreconnaissance11
T1598.003 Spearphishing Linkreconnaissance00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-33739Microsoft Windows T1598.002 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1595 Mapped