kevmap

Log sources › OpenBSM:AuditTrail

OpenBSM:AuditTrail

Inverted view: what can be detected if this is the log you have. macOS

2
channels
2
analytics
2
techniques
0
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
BSM audit events for file permission, ownership, and attribute modifications with user context DC0059 File Metadata AN0999 1
open/openat of /dev/bpf*; ioctl BIOCSETF-like operations. DC0032 Process Creation AN0464 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1205.002 Socket Filtersstealth, persistence, command and control00
T1222.002 Linux and Mac Permissionsdefense impairment40