kevmap

Log sources › saas:box

saas:box

Inverted view: what can be detected if this is the log you have. SaaS

3
channels
3
analytics
3
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API calls exceeding baseline thresholds DC0085 Network Traffic Content AN1514 1
User navigated to admin interface DC0038 Application Log Content AN0811 1
collaboration.invite DC0027 Cloud Storage Metadata AN1582 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1537 Transfer Data to Cloud Accountexfiltration60
T1538 Cloud Service Dashboarddiscovery00
T1567 Exfiltration Over Web Serviceexfiltration123

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-41082Microsoft Exchange Server T1567 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2025-54309CrushFTP CrushFTP T1567 Mapped