Log sources › NSM:Firewall
NSM:Firewall
Inverted view: what can be detected if this is the log you have. ESXi, Network Devices, Windows, macOS
12
channels
12
analytics
10
techniques
6
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Anomalous TCP SYN or ACK spikes from specific source or interface |
DC0085 Network Traffic Content | AN1014 | 1 |
High rate of inbound TCP SYN or ACK packets with missing 3-way handshake completion |
DC0085 Network Traffic Content | AN1012 | 1 |
ICMP/UDP protocol anomaly |
DC0085 Network Traffic Content | AN1258 | 1 |
Outbound Connections |
DC0082 Network Connection Creation | AN0161 | 1 |
Outbound connections to 139/445 to multiple destinations |
DC0078 Network Traffic Flow | AN0515 | 1 |
Outbound encrypted traffic |
DC0085 Network Traffic Content | AN1024 | 1 |
Policy Change / Rule Update |
DC0051 Firewall Rule Modification | AN1233 | 1 |
TLS/HTTP inspection |
DC0085 Network Traffic Content | AN0567 | 1 |
inbound connection to port 5900 |
DC0078 Network Traffic Flow | AN0506 | 1 |
pf firewall logs |
DC0078 Network Traffic Flow | AN1231 | 1 |
proxy or TLS inspection logs |
DC0082 Network Connection Creation | AN0285 | 1 |
rule_modification: New or modified firewall rules related to wireless interfaces |
DC0051 Firewall Rule Modification | AN1479 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1021.005 VNC | lateral movement | 1 | 0 |
| T1056 Input Capture | collection, credential access | 2 | 3 |
| T1090 Proxy | command and control | 22 | 3 |
| T1090.003 Multi-hop Proxy | command and control | 3 | 0 |
| T1090.004 Domain Fronting | command and control | 1 | 0 |
| T1095 Non-Application Layer Protocol | command and control | 3 | 0 |
| T1102.001 Dead Drop Resolver | command and control | 4 | 0 |
| T1135 Network Share Discovery | discovery | 7 | 0 |
| T1499.001 OS Exhaustion Flood | impact | 1 | 0 |
| T1669 Wi-Fi Networks | initial access | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1090 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1090 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1056 | Mapped |