kevmap

Log sources › networkconfig

networkconfig

Inverted view: what can be detected if this is the log you have. Linux, Network Devices

2
channels
2
analytics
2
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
interface flag PROMISC, netstat | ip link | ethtool DC0085 Network Traffic Content AN0876 1
unexpected OS image file upload or modification events DC0061 File Modification AN0758 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1040 Network Sniffingcredential access, discovery92
T1556.004 Network Device Authenticationdefense impairment, persistence, credential access10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2022-1040Sophos Firewall T1040 Mapped