kevmap

Log sources › saas:confluence

saas:confluence

Inverted view: what can be detected if this is the log you have. SaaS

3
channels
2
analytics
2
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
REST API access from non-browser agents DC0085 Network Traffic Content AN1019 1
access.content DC0038 Application Log Content AN1019 AN1162 2
logon DC0067 Logon Session Creation AN1019 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1213 Data from Information Repositoriescollection72
T1213.001 Confluencecollection00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-24086Adobe Commerce and Magento Open Source T1213 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1213 Mapped