Log sources › PF:Logs
PF:Logs
Inverted view: what can be detected if this is the log you have. macOS
3
channels
3
analytics
3
techniques
25
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
External traffic to remote access services |
DC0078 Network Traffic Flow | AN1006 | 1 |
high out:in ratio or fixed-size periodic flows |
DC0078 Network Traffic Flow | AN0929 | 1 |
outbound flows with bytes_out >> bytes_in |
DC0078 Network Traffic Flow | AN0347 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1132.001 Standard Encoding | command and control | 4 | 0 |
| T1132.002 Non-Standard Encoding | command and control | 0 | 0 |
| T1133 External Remote Services | persistence, initial access | 20 | 25 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1133 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1133 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1133 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1133 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1133 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1133 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1133 | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1133 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1133 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1133 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1133 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1133 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1133 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1133 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1133 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1133 | Mapped |