Log sources › NSM:Flow
NSM:Flow
Inverted view: what can be detected if this is the log you have. Containers, ESXi, Linux, Network Devices, Windows, macOS
229
channels
235
analytics
131
techniques
274
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions |
DC0078 Network Traffic Flow | AN1274 | 1 |
Abnormal browser traffic volume or destination |
DC0078 Network Traffic Flow | AN0253 | 1 |
Altered response metadata or blocked content based on user-agent or geolocation |
DC0106 Response Metadata | AN1149 | 1 |
Base64 strings or gzip in URI, headers, or POST body |
DC0085 Network Traffic Content | AN0303 | 1 |
Browser connections to known C2 or dynamic DNS domains |
DC0085 Network Traffic Content | AN0125 | 1 |
C2 exfiltration |
DC0085 Network Traffic Content | AN0653 | 1 |
Captured File Content |
DC0085 Network Traffic Content | AN0652 | 1 |
Closed-port hits followed by success from same src_ip |
DC0082 Network Connection Creation | AN1450 | 1 |
Connection Tracking |
DC0078 Network Traffic Flow | AN1230 | 1 |
Connections from IDE hosts to marketplace/tunnel domains |
DC0078 Network Traffic Flow | AN1549 | 1 |
Connections to *.devtunnels.ms or tunnels.api.visualstudio.com |
DC0082 Network Connection Creation | AN0376 | 1 |
Connections to TCP 427 (SLP) or vCenter web services from untrusted sources |
DC0085 Network Traffic Content | AN0224 | 1 |
Content injection observed in HTTPS responses with mismatched certificates or altered payloads |
DC0085 Network Traffic Content | AN0994 | 1 |
DHCP OFFER or ACK with unauthorized DNS/gateway parameters |
DC0085 Network Traffic Content | AN1290 | 1 |
Degraded encryption throughput or switch to weaker cipher suites compared to historical baselines |
DC0085 Network Traffic Content | AN1360 | 1 |
Device-to-Device Deployment Flows |
DC0078 Network Traffic Flow | AN0627 | 1 |
DrsAddEntry, DrsReplicaAdd, GetNCChanges calls between non-DC and DCs. |
DC0085 Network Traffic Content | AN0770 | 1 |
Egress to non-approved networks from host after terminal exec |
DC0085 Network Traffic Content | AN0964 | 1 |
Encrypted tunnels or proxy traffic to non-standard destinations |
DC0085 Network Traffic Content | AN1151 | 1 |
Excessive gratuitous ARP replies on local subnet |
DC0085 Network Traffic Content | AN1093 | 1 |
External access to container ports (2375, 6443) |
DC0082 Network Connection Creation | AN1007 | 1 |
First-time egress from host after new install to unknown update endpoints |
DC0078 Network Traffic Flow | AN1480 | 1 |
First-time egress to new registries/CDNs post-install/build |
DC0078 Network Traffic Flow | AN0022 | 1 |
First-time egress to non-approved registries after dependency install |
DC0078 Network Traffic Flow | AN0023 | 1 |
First-time egress to non-approved update hosts right after install/update |
DC0078 Network Traffic Flow | AN0862 | 1 |
First-time egress to unknown registries/mirrors immediately after install |
DC0078 Network Traffic Flow | AN1481 | 1 |
First-time outbound connections to package registries or unknown hosts immediately after restore/build |
DC0078 Network Traffic Flow | AN0021 | 1 |
Flow Creation (NetFlow/sFlow) |
DC0078 Network Traffic Flow | AN1233 | 1 |
Flow records with RSA key exchange on unexpected port |
DC0078 Network Traffic Flow | AN1500 | 1 |
Flow records with entropy signatures resembling symmetric encryption |
DC0078 Network Traffic Flow | AN0404 | 1 |
Flow/PCAP analysis for outbound payloads |
DC0085 Network Traffic Content | AN0988 | 1 |
Gratuitous ARP replies with mismatched IP-MAC binding |
DC0078 Network Traffic Flow | AN1092 | 1 |
Gratuitous or duplicate DHCP OFFER packets from non-legitimate servers |
DC0078 Network Traffic Flow | AN1291 | 1 |
HTTP |
DC0085 Network Traffic Content | AN0144 | 1 |
HTTP Request Logging |
DC0085 Network Traffic Content | AN1320 | 1 |
HTTP payloads with SQLi/LFI/JNDI/deserialization indicators |
DC0085 Network Traffic Content | AN0220 | 1 |
HTTP(S) requests with User-Agents typical of PowerShell or curl from desktop; or URIs matching paste-inspired payload hosts |
DC0085 Network Traffic Content | AN0962 | 1 |
HTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects) |
DC0085 Network Traffic Content | AN0500 | 1 |
HTTP/TLS Logs |
DC0085 Network Traffic Content | AN0159 | 1 |
HTTP/WebDAV requests that contain NTLMSSP or PROPFIND/MOVE/OPTIONS with Authorization: NTLM |
DC0085 Network Traffic Content | AN0065 | 1 |
HTTPS API requests to Dropbox, iCloud, Google Drive, OneDrive shortly after DB tool usage |
DC0085 Network Traffic Content | AN0678 | 1 |
HTTPs connection to tunnels.api.visualstudio.com |
DC0082 Network Connection Creation | AN0377 | 1 |
High volume flows with incomplete TCP sessions or single-packet bursts |
DC0078 Network Traffic Flow | AN1435 | 1 |
High volumes of SYN/ACK packets with unacknowledged TCP handshakes |
DC0078 Network Traffic Flow | AN1013 | 1 |
High-volume or repeated SNMP GETBULK/GETNEXT queries from untrusted or external IPs |
DC0082 Network Connection Creation | AN1249 | 1 |
ICMP/UDP monitoring (tcpdump, Wireshark, Zeek) |
DC0085 Network Traffic Content | AN1256 | 1 |
ICMP/UDP traffic (Wireshark, Suricata, Zeek) |
DC0085 Network Traffic Content | AN1254 | 1 |
Inbound HTTP POST with suspicious payload size or user-agent |
DC0085 Network Traffic Content | AN1108 AN2029 AN2032 | 2 |
Inbound connections to 445, 3389, 5985-5986 with high error/connection-reset rate, followed by new outbound sessions from the same host to internal assets within short interval. |
DC0085 Network Traffic Content | AN0327 | 1 |
Inbound connections to monitored service ports from external or unusual internal sources; rapid follow-on lateral connections from the same host. |
DC0085 Network Traffic Content | AN0328 | 1 |
Inbound one-off packet to uncommon port → outbound SF to same src_ip within TimeWindow. |
DC0085 Network Traffic Content | AN0464 | 1 |
Inbound to 22/5900/8080 and follow-on internal connections. |
DC0085 Network Traffic Content | AN0330 | 1 |
Inbound to tcp/427 (OpenSLP), tcp/443 (vSphere APIs), tcp/902, tcp/5989 followed by new unexpected outbound sessions from the ESXi/vCenter host. |
DC0085 Network Traffic Content | AN0329 | 1 |
Injected content responses with unexpected script/malware signatures |
DC0085 Network Traffic Content | AN0993 | 1 |
Inter-segment traffic |
DC0078 Network Traffic Flow | AN0208 | 1 |
Knock pattern: multiple REJ/S0 to distinct closed ports then successful connection to service_port |
DC0078 Network Traffic Flow | AN1449 | 1 |
Knock pattern: repeated REJ/S0 across ≥MinSequenceLen ports from same src_ip then SF success. |
DC0078 Network Traffic Flow | AN0843 | 1 |
LDAP Bind/Search |
DC0085 Network Traffic Content | AN0363 | 1 |
LDAP Query |
DC0085 Network Traffic Content | AN0364 | 1 |
LEASE_GRANTED |
DC0078 Network Traffic Flow | AN0186 | 1 |
Long-lived or hijacked SSH sessions maintained with no active user activity |
DC0078 Network Traffic Flow | AN0217 | 1 |
MAC not in allow-list acquiring IP (DHCP) |
DC0078 Network Traffic Flow | AN0187 | 1 |
Multiple DHCP OFFER responses for a single DISCOVER |
DC0085 Network Traffic Content | AN1292 | 1 |
NetFlow/Zeek conn.log |
DC0078 Network Traffic Flow | AN0368 | 1 |
NetFlow/sFlow for odd egress to Internet from mgmt plane |
DC0085 Network Traffic Content | AN0225 | 1 |
NetFlow/sFlow/PCAP |
DC0078 Network Traffic Flow | AN0596 | 1 |
Network Capture TLS/HTTP |
DC0085 Network Traffic Content | AN1295 | 1 |
New VM egress to crypto-mining pools or non-approved Internet ranges within minutes of boot |
DC0085 Network Traffic Content | AN0692 | 1 |
New egress from app just installed to unknown update endpoints |
DC0078 Network Traffic Flow | AN1482 | 1 |
New egress from container IP/namespace to Internet or non-approved CIDRs/ASNs |
DC0085 Network Traffic Content | AN0691 | 1 |
New egress to Internet by the same UID/host shortly after terminal exec |
DC0082 Network Connection Creation | AN0963 | 1 |
New outbound flows to non-approved vendor hosts post install |
DC0078 Network Traffic Flow | AN0863 | 1 |
New/rare egress to non-approved update hosts after install |
DC0078 Network Traffic Flow | AN0864 | 1 |
None |
DC0078 Network Traffic Flow | AN0213 AN1378 | 2 |
Observed File Transfers |
DC0059 File Metadata | AN0652 | 1 |
Observed downgrade in negotiated cipher suites or TLS/SSH versions across sessions |
DC0085 Network Traffic Content | AN0681 | 1 |
Outbound Connections |
DC0082 Network Connection Creation | AN1114 AN1119 | 2 |
Outbound HTTP/S |
DC0085 Network Traffic Content | AN1408 | 1 |
Outbound HTTP/S initiated by newly installed interpreter process |
DC0082 Network Connection Creation | AN0700 | 1 |
Outbound Network Flow |
DC0078 Network Traffic Flow | AN0597 | 1 |
Outbound SCP, TFTP, or FTP sessions carrying configuration file content |
DC0085 Network Traffic Content | AN0647 | 1 |
Outbound TCP SYN or UDP to multiple ports/hosts |
DC0078 Network Traffic Flow | AN1058 | 1 |
Outbound UDP floods targeting common reflection services with spoofed IP headers |
DC0078 Network Traffic Flow | AN1141 | 1 |
Outbound connection to *.tunnels.api.visualstudio.com or *.devtunnels.ms |
DC0082 Network Connection Creation | AN0375 | 1 |
Outbound connection to mining pool port (3333, 4444, 5555) |
DC0078 Network Traffic Flow | AN1490 | 1 |
Outbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs |
DC0078 Network Traffic Flow | AN1508 | 1 |
Outbound connections to TCP 139,445 and HTTP/HTTPS to WebDAV endpoints from workstation subnets |
DC0078 Network Traffic Flow | AN0065 | 1 |
Outbound flow records |
DC0078 Network Traffic Flow | AN0926 | 1 |
Outbound or inbound TFTP file transfers of ROMMON or firmware binaries |
DC0082 Network Connection Creation | AN0497 | 1 |
Outbound requests to domains not previously resolved or associated with phishing campaigns |
DC0078 Network Traffic Flow | AN0299 | 1 |
Outbound traffic from suspicious new processes post-attachment execution |
DC0078 Network Traffic Flow | AN0656 | 1 |
Outbound traffic spike through formerly blocked ports/subnets following config change |
DC0082 Network Connection Creation | AN0855 | 1 |
Outbound traffic to domains/IPs not previously resolved, occurring shortly after attachment download or link click |
DC0078 Network Traffic Flow | AN0321 | 1 |
Outbound traffic to mining pool upon container launch |
DC0078 Network Traffic Flow | AN1492 | 1 |
Outbound traffic to mining pools or proxies |
DC0078 Network Traffic Flow | AN0742 | 1 |
PCAP inspection |
DC0085 Network Traffic Content | AN0427 | 1 |
POST requests to .php, .jsp, .aspx files with high entropy body |
DC0085 Network Traffic Content | AN1109 | 1 |
Packets with unusual flags or payloads outside established flows (e.g., WoL magic FF×6 + 16×MAC) |
DC0085 Network Traffic Content | AN1449 | 1 |
Port-knock pattern from one src to device unicast,broadcast,network addresses on same port within TimeWindowKnock |
DC0082 Network Connection Creation | AN1451 | 1 |
Probe responses from unauthorized APs responding to client probe requests |
DC0085 Network Traffic Content | AN1069 | 1 |
Rare inbound packet characteristics (ICMP/UDP/TCP to uncommon port) from src_ip followed ≤TimeWindow by outbound SF from same host to src_ip. |
DC0085 Network Traffic Content | AN0463 | 1 |
Relay patterns across IP hops |
DC0085 Network Traffic Content | AN1023 | 1 |
Relayed session pathing (multi-hop) |
DC0078 Network Traffic Flow | AN1024 | 1 |
Requests towards cloud metadata or command & control from pod IPs |
DC0085 Network Traffic Content | AN0222 | 1 |
SMB2_LOGOFF/SMB_TREE_DISCONNECT |
DC0085 Network Traffic Content | AN0286 | 1 |
SPAN or port-mirrored HTTP/S |
DC0085 Network Traffic Content | AN0078 | 1 |
SSH logins or scp activity |
DC0085 Network Traffic Content | AN0195 | 1 |
SSL/TLS Handshake Analysis |
DC0085 Network Traffic Content | AN1294 | 1 |
SSL/TLS Inspection or PCAP |
DC0085 Network Traffic Content | AN1189 | 1 |
Sequence of REJ/S0 then SF success from same src_ip within TimeWindow. |
DC0082 Network Connection Creation | AN0844 | 1 |
Series of denied/closed flows to distinct ports then success to mgmt port from same src_ip within TimeWindow. |
DC0082 Network Connection Creation | AN0845 | 1 |
Session History Reset |
DC0085 Network Traffic Content | AN0136 | 1 |
Session Transfer Content |
DC0085 Network Traffic Content | AN0651 | 1 |
Session records with TLS-like byte patterns |
DC0078 Network Traffic Flow | AN0763 | 1 |
Single, low-volume inbound packet (REJ/S0/OTH or uncommon dport/protocol) from src_ip followed by outbound SF connection to src_ip. |
DC0085 Network Traffic Content | AN0462 | 1 |
Source/destination IP translation inconsistent with intended policy |
DC0078 Network Traffic Flow | AN0465 | 1 |
Sudden spike in incoming flows to web service ports from single/multiple IPs |
DC0078 Network Traffic Flow | AN0490 | 1 |
Suspicious POSTs to upload endpoints |
DC0085 Network Traffic Content | AN1623 | 1 |
Suspicious URL patterns, uncommon TLDs, URL shorteners |
DC0085 Network Traffic Content | AN0179 | 1 |
Suspicious URL patterns, uncommon TLDs, short-lived domains, URL shorteners; HTTP method GET/POST |
DC0085 Network Traffic Content | AN0178 | 1 |
Suspicious changes in TLS certificate responses or redirected domains |
DC0104 Response Content | AN1150 | 1 |
Suspicious long-lived or reattached remote desktop sessions from unexpected IPs |
DC0085 Network Traffic Content | AN0218 | 1 |
Sustained abnormal inbound request rate targeting application ports (e.g., 80/443/25) |
DC0085 Network Traffic Content | AN1166 | 1 |
TCP port 22 traffic |
DC0078 Network Traffic Flow | AN1638 | 1 |
TCP port 5900 open |
DC0078 Network Traffic Flow | AN0505 | 1 |
TCP session tracking |
DC0085 Network Traffic Content | AN0031 | 1 |
TCP/UDP |
DC0085 Network Traffic Content | AN0030 | 1 |
TCP: possible SYN flood or backlog limit exceeded |
DC0018 Host Status | AN1013 | 1 |
TGS-REQ and AS-REQ seen for new user shortly after domain-modifying process |
DC0002 User Account Authentication | AN0007 | 1 |
TLS downgrade or inconsistent DNS answers |
DC0085 Network Traffic Content | AN0825 | 1 |
Traffic patterns showing downgrade from strong encryption (AES-256) to weaker or plaintext protocols |
DC0085 Network Traffic Content | AN0961 | 1 |
Traffic spike preceding control crash |
DC0085 Network Traffic Content | AN2040 | 1 |
Transferred file observations |
DC0085 Network Traffic Content | AN0654 | 1 |
Unexpected ARP replies or DNS responses inconsistent with authoritative servers |
DC0085 Network Traffic Content | AN0824 | 1 |
Unexpected flows between segmented networks or prohibited ports |
DC0078 Network Traffic Flow | AN0015 | 1 |
Unexpected inbound/outbound TFTP traffic for device image files |
DC0082 Network Connection Creation | AN1603 | 1 |
Unexpected or unauthorized inbound connections to SNMP, NETCONF, or RESTCONF services |
DC0082 Network Connection Creation | AN1630 | 1 |
Unexpected route changes or duplicate gateway advertisements |
DC0078 Network Traffic Flow | AN0826 | 1 |
Unexpected script or binary content returned in HTTP response body |
DC0085 Network Traffic Content | AN0992 | 1 |
Unusual Base64-encoded content in URI, headers, or POST body |
DC0085 Network Traffic Content | AN0302 | 1 |
Unusual request pattern leading up to service crash (e.g., malformed or oversized payload) |
DC0085 Network Traffic Content | AN0851 | 1 |
Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts |
DC0085 Network Traffic Content | AN1274 | 1 |
alert log |
DC0078 Network Traffic Flow | AN0923 | 1 |
alternate ports |
DC0078 Network Traffic Flow | AN1377 | 1 |
conn.log |
DC0078 Network Traffic Flow DC0082 Network Connection Creation DC0085 Network Traffic Content |
AN0101 AN0205 AN0207 AN0925 AN1232 AN1382 | 5 |
conn.log + files.log + ssl.log |
DC0085 Network Traffic Content | AN0989 | 1 |
conn.log + ssl.log with Tor fingerprinting |
DC0078 Network Traffic Flow | AN1021 | 1 |
conn.log or flow data |
DC0078 Network Traffic Flow | AN1390 | 1 |
conn.log or http.log |
DC0085 Network Traffic Content | AN0923 | 1 |
conn.log, http.log, dns.log, ssl.log |
DC0085 Network Traffic Content | AN1228 | 1 |
conn.log, icmp.log |
DC0078 Network Traffic Flow | AN1258 | 1 |
conn.log, ssl.log |
DC0085 Network Traffic Content | AN1190 | 1 |
connection attempts |
DC0082 Network Connection Creation | AN1231 | 1 |
connection metadata |
DC0078 Network Traffic Flow | AN0169 | 1 |
connection: Inbound connections to SSH or VPN ports |
DC0082 Network Connection Creation | AN1005 | 1 |
connection: SMB connections to multiple internal hosts |
DC0082 Network Connection Creation | AN0515 | 1 |
connection: TCP connections to ports 139/445 to multiple hosts |
DC0082 Network Connection Creation | AN0514 | 1 |
container egress to unknown IPs/domains |
DC0085 Network Traffic Content | AN1317 | 1 |
dns, ssl, conn |
DC0085 Network Traffic Content | AN1226 | 1 |
dns.log |
DC0085 Network Traffic Content | AN1121 AN1122 AN1124 AN1125 | 1 |
flow records |
DC0078 Network Traffic Flow | AN0424 AN0426 | 1 |
ftp.log, conn.log |
DC0085 Network Traffic Content | AN1170 | 1 |
ftp.log, conn.log, smb_files.log |
DC0085 Network Traffic Content | AN1173 | 1 |
ftp.log, smb_files.log |
DC0085 Network Traffic Content | AN1169 | 1 |
host switch egress data |
DC0085 Network Traffic Content | AN1392 | 1 |
http, dns, smb, ssl logs |
DC0085 Network Traffic Content | AN1225 | 1 |
http.log |
DC0085 Network Traffic Content | AN0285 AN0426 | 2 |
http.log, conn.log |
DC0085 Network Traffic Content | AN0076 AN2031 | 2 |
http.log, files.log |
DC0085 Network Traffic Content | AN0058 | 1 |
http.log, ftp.log |
DC0085 Network Traffic Content | AN0423 AN0424 AN0425 | 1 |
http.log, ssl.log |
DC0085 Network Traffic Content | AN0075 | 1 |
http.log, ssl.log, websocket.log |
DC0085 Network Traffic Content | AN0079 | 1 |
http.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources |
DC0085 Network Traffic Content | AN0498 | 1 |
http/file-xfer: Inbound/outbound transfer of ELF shared objects |
DC0085 Network Traffic Content | AN0053 | 1 |
http/file-xfer: Outbound transfer of large video-like MIME types soon after capture |
DC0085 Network Traffic Content | AN0569 | 1 |
http: Base64/MIME looking payloads from ESXi host IP |
DC0085 Network Traffic Content | AN0348 | 1 |
http: HTTP bodies from ESXi host IPs containing long, non-standard tokens |
DC0085 Network Traffic Content | AN0930 | 1 |
http: HTTP bodies/headers contain long tokens with non-standard alphabets or constant-size periodic POSTs |
DC0085 Network Traffic Content | AN0928 | 1 |
http: HTTP body contains long Base64 sections |
DC0085 Network Traffic Content | AN0347 | 1 |
http: HTTP body or headers contain long Base64 sections; gzip/deflate + Base64 |
DC0085 Network Traffic Content | AN0346 | 1 |
http: suspicious long tokens with custom alphabets in body/headers |
DC0085 Network Traffic Content | AN0929 | 1 |
http::post: Outbound HTTP POST from host shortly after DB export activity |
DC0085 Network Traffic Content | AN0676 | 1 |
http::request: Network connection to package registry or C2 from interpreter shortly after install |
DC0085 Network Traffic Content | AN0698 | 1 |
http::request: Outbound HTTP initiated by Python interpreter |
DC0085 Network Traffic Content | AN0713 | 1 |
http::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domains |
DC0085 Network Traffic Content | AN0499 | 1 |
icmp.log, weird.log |
DC0085 Network Traffic Content | AN1255 | 1 |
large HTTPS POST requests to text storage domains |
DC0085 Network Traffic Content | AN0788 | 1 |
large HTTPS POST requests to webhook endpoints |
DC0085 Network Traffic Content | AN0437 | 1 |
large HTTPS outbound uploads |
DC0078 Network Traffic Flow | AN1572 | 1 |
large outbound HTTPS uploads to repo domains |
DC0078 Network Traffic Flow | AN0896 | 1 |
large outbound data flows or long-duration connections |
DC0078 Network Traffic Flow | AN0081 | 1 |
large transfer from management IPs to unauthorized host |
DC0085 Network Traffic Content | AN1159 | 1 |
large upload to firmware interface port or path |
DC0085 Network Traffic Content | AN0477 | 1 |
ldap.log |
DC0085 Network Traffic Content | AN1026 | 1 |
log entries indicating network connection initiation on macOS |
DC0082 Network Connection Creation | AN2065 | 1 |
mirror/SPAN port |
DC0085 Network Traffic Content | AN1172 | 1 |
mqtt.log / xmpp.log (custom log feeds) |
DC0085 Network Traffic Content | AN0002 | 1 |
mqtt.log or AMQP custom log |
DC0085 Network Traffic Content | AN0003 | 1 |
mqtt.log, xmpp.log, amqp.log |
DC0085 Network Traffic Content | AN0005 | 1 |
network_flow: bytes_out >> bytes_in, fixed packet sizes/intervals to non-approved CIDRs |
DC0078 Network Traffic Flow | AN0930 | 1 |
new outbound connection from browser/office lineage |
DC0082 Network Connection Creation | AN1315 | 1 |
new outbound connection from exploited lineage |
DC0082 Network Connection Creation | AN1316 | 1 |
outbound connections from host during or immediately after image build |
DC0082 Network Connection Creation | AN1261 | 1 |
outbound connections to RMM services or to unusual destination ports |
DC0082 Network Connection Creation | AN0715 | 1 |
outbound egress from web host after suspicious request |
DC0085 Network Traffic Content | AN0221 | 1 |
packet capture or DPI logs |
DC0085 Network Traffic Content | AN0246 | 1 |
pf firewall logs |
DC0078 Network Traffic Flow | AN0206 AN0924 | 2 |
port 5900 inbound |
DC0078 Network Traffic Flow | AN0504 | 1 |
query: High-volume LDAP traffic with filters targeting groupPolicyContainer attributes |
DC0085 Network Traffic Content | AN0152 | 1 |
remote CLI session detection |
DC0085 Network Traffic Content | AN0399 | 1 |
remote access |
DC0082 Network Connection Creation | AN1084 | 1 |
remote login and transfer |
DC0085 Network Traffic Content | AN0196 | 1 |
session behavior |
DC0085 Network Traffic Content | AN0032 | 1 |
session stats with bytes_out > bytes_in |
DC0078 Network Traffic Flow | AN0989 | 1 |
smb_command: TreeConnectAndX to \\*\IPC$ / srvsvc or Trans2/NT_CREATE for listing shares |
DC0021 OS API Execution | AN0514 | 1 |
smb_files.log |
DC0102 Network Share Access | AN1299 | 1 |
smtp.log |
DC0085 Network Traffic Content | AN0379 | 1 |
smtp.log, conn.log |
DC0085 Network Traffic Content | AN0380 AN0382 | 1 |
ssh connections originating from third-party CIDRs |
DC0085 Network Traffic Content | AN1345 | 1 |
ssh/smb connections to internal resources from third-party devices |
DC0085 Network Traffic Content | AN1346 | 1 |
ssl.log |
DC0085 Network Traffic Content | AN0101 | 1 |
ssl.log (for TLS handshake analysis), dns.log (tunneling indicators) |
DC0085 Network Traffic Content | AN1390 | 1 |
ssl.log + http.log |
DC0085 Network Traffic Content | AN0565 | 1 |
ssl.log - Certificate Analysis |
DC0085 Network Traffic Content | AN1413 | 1 |
ssl.log, conn.log |
DC0085 Network Traffic Content | AN1414 | 1 |
ssl.log, x509.log |
DC0085 Network Traffic Content | AN1415 | 1 |
sustained outbound HTTPS sessions with high data volume |
DC0078 Network Traffic Flow | AN1512 | 1 |
uncommon ports |
DC0078 Network Traffic Flow | AN1376 | 1 |
unexpected network activity initiated shortly after shell session starts |
DC0085 Network Traffic Content | AN0059 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | T1190 | Mapped |
| CVE-2009-4324 | Adobe Acrobat and Reader | T1071.001 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1105 T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1105 T1189 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2011-0611 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-0754 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1204.001 | Mapped |
| CVE-2012-1535 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-0625 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0629 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0631 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0632 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0640 | Adobe Reader and Acrobat | T1566.001 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 T1105 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 T1499.004 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1071.001 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1071.001 T1105 T1204.001 T1566.002 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1105 T1189 | Mapped |
| CVE-2016-0984 | Adobe Flash Player and AIR | T1105 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 T1190 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1105 T1189 | Mapped |
| CVE-2016-4117 | Adobe Flash Player | T1105 | Mapped |
| CVE-2016-4437 | Apache Shiro | T1190 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1105 T1566.001 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1566.001 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1190 | Mapped |
| CVE-2017-5638 | Apache Struts | T1190 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 T1542.005 | Mapped |
| CVE-2017-9805 | Apache Struts | T1190 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1190 T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1190 T1496 | Mapped |
| CVE-2018-13379 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1190 T1491.002 | Mapped |
| CVE-2018-15982 | Adobe Flash Player | T1105 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1041 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 T1190 | Mapped |
| CVE-2018-6789 | Exim Exim | T1190 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1190 T1496 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1041 T1190 T1505.003 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 T1133 T1498 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1133 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1046 T1190 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1046 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1190 | Mapped |
| CVE-2019-17558 | Apache Solr | T1190 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 T1190 T1496 T1505.003 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 T1133 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1133 T1557 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1087.002 T1133 | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | T1190 | Mapped |
| CVE-2020-17530 | Apache Struts | T1190 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1133 | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | T1190 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1204.001 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1133 T1190 T1552 | Stale |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1056 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1133 T1496 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-21972 | VMware vCenter Server | T1190 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 T1190 | Mapped |
| CVE-2021-21975 | VMware vRealize Operations Manager API | T1190 | Mapped |
| CVE-2021-22005 | VMware vCenter Server | T1190 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 T1190 | Mapped |
| CVE-2021-22204 | Perl Exiftool | T1190 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1190 T1496 T1498 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1190 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1090 T1133 T1190 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1190 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1090 T1133 T1505.003 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 T1505.003 | Mapped |
| CVE-2021-26858 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27065 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1190 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1190 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1190 | Mapped |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | T1190 T1505.003 | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | T1190 | Mapped |
| CVE-2021-3129 | Laravel Ignition | T1190 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 T1190 | Mapped |
| CVE-2021-34523 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1071.001 T1105 T1190 T1496 | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | T1190 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 T1190 | Mapped |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | T1190 | Mapped |
| CVE-2021-39144 | XStream XStream | T1190 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1190 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1071.001 T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1087.002 T1190 T1505.003 T1573.001 | Mapped |
| CVE-2021-40655 | D-Link DIR-605 Router | T1190 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1087.002 T1190 T1505.003 T1573.001 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1190 T1496 T1505.003 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1105 T1190 | Mapped |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | T1190 T1195.002 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1071 T1190 T1499.002 | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | T1190 T1498 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1190 T1557 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1133 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1190 | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1190 | Mapped |
| CVE-2022-20821 | Cisco IOS XR | T1190 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1204.001 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1190 | Mapped |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager | T1505.003 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1190 T1505.003 | Mapped |
| CVE-2022-22965 | VMware Spring Framework | T1190 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1190 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1190 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1204.001 | Mapped |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | T1190 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1190 T1499.002 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1048 T1190 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1048 T1190 | Mapped |
| CVE-2022-28810 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 T1505 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1190 T1496 | Mapped |
| CVE-2022-30190 | Microsoft Windows | T1105 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1204.001 | Mapped |
| CVE-2022-3075 | Google Chromium Mojo | T1204.001 | Mapped |
| CVE-2022-35914 | Teclib GLPI | T1190 | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | T1190 | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | T1190 | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | T1190 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1566.001 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1505.003 T1567 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1071.001 T1190 | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | T1190 | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1190 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1190 T1210 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 T1496 T1498 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1505.003 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1190 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1133 | Mapped |
| CVE-2023-20867 | VMware Tools | T1105 | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | T1190 | Mapped |
| CVE-2023-2136 | Google Chromium Skia | T1204.001 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1190 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1105 T1190 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1190 T1505.003 | Stale |
| CVE-2023-2533 | PaperCut NG/MF | T1566.002 | Mapped |
| CVE-2023-26359 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1046 T1071.001 T1105 T1190 T1505.003 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1105 T1190 | Mapped |
| CVE-2023-27524 | Apache Superset | T1190 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1133 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1190 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 T1105 T1566.001 | Mapped |
| CVE-2023-29298 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-29492 | Novi Survey Novi Survey | T1190 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1087.002 T1496 T1505.003 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1190 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1105 T1190 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1087.002 T1105 T1190 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36845 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36846 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36847 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36851 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1046 T1071.001 T1105 T1190 T1496 T1557.001 | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-38205 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1041 T1059.004 T1105 T1204 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1190 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 T1059.004 T1133 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1071.002 | Mapped |
| CVE-2023-42793 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1190 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 T1190 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1190 T1505.003 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 T1498 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1133 T1190 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1105 T1190 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1190 T1552 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 T1498 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1204.001 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 T1204.001 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1105 T1190 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1190 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 T1498 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1567 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1190 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | T1190 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1566.002 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1190 T1505.003 T1552 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1190 T1505.003 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1105 T1496 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 T1059.004 T1566.002 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1190 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 T1204.001 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1190 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1056 T1566.002 | Mapped |
| CVE-2024-4358 | Progress Telerik Report Server | T1190 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1133 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1041 T1071.001 T1190 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1190 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1190 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1195 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1071.001 T1105 T1195.002 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1011 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1011 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1199 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1210 T1495 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1041 T1190 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1190 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1190 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1046 T1190 | Mapped |
| CVE-2025-0411 | 7-Zip 7-Zip | T1566.001 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1190 | Mapped |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | T1495 | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1190 | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | T1190 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1204 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 T1190 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1499.004 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1001 T1105 T1557 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1001 T1105 T1557 | Stale |
| CVE-2025-31324 | SAP NetWeaver | T1505.003 T1602 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1041 T1046 T1133 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 T1056.001 T1566.001 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1190 | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | T1190 T1505.003 | Mapped |
| CVE-2025-3928 | Commvault Web Server | T1505.003 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1190 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1190 T1505.003 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1105 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 T1505.003 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |
| CVE-2025-49704 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1190 T1505 | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1567 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1190 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1498 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |