kevmap

Log sources › networkdevice:Firewall

networkdevice:Firewall

Inverted view: what can be detected if this is the log you have. Network Devices

3
channels
1
analytics
1
techniques
0
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Audit trail or CLI/API access indicating commands like no access-list, delete rule-set, clear config DC0064 Command Execution AN0855 1
Login from untrusted IP, or new admin account accessing firewall console/API DC0067 Logon Session Creation AN0855 1
update_rule: Access control or NAT rule modified or disabled outside maintenance window DC0051 Firewall Rule Modification AN0855 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1686.002 Network Device Firewalldefense impairment20