kevmap

Log sources › VPCFlowLogs:All

VPCFlowLogs:All

Inverted view: what can be detected if this is the log you have. IaaS

1
channels
1
analytics
1
techniques
7
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
High volume internal traffic with low entropy indicating looped or malicious DoS script DC0078 Network Traffic Flow AN0587 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1499 Endpoint Denial of Serviceimpact37

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1499 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 Mapped
CVE-2024-54085AMI MegaRAC SPx T1499 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped