Log sources › WinEventLog:Application
WinEventLog:Application
Inverted view: what can be detected if this is the log you have. Office Suite, Windows
20
channels
22
analytics
22
techniques
98
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
API call to AddMonitor invoked by non-installer process |
DC0021 OS API Execution | AN0580 | 1 |
Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events |
DC0038 Application Log Content | AN0498 | 1 |
CLR Assembly creation, loading, or modification logs via MSSQL CLR integration |
DC0016 Module Load | AN0511 | 1 |
EventCode=1000 |
DC0038 Application Log Content | AN0540 AN0797 AN0850 AN1314 | 4 |
Exchange Transport Service loads unusual .NET assembly or errors upon transport agent execution |
DC0038 Application Log Content | AN0472 | 1 |
Exchange logs or header artifacts |
DC0038 Application Log Content | AN1309 | 1 |
High-frequency errors or hangs from resource-intensive application components (e.g., .NET, IIS, Office Suite) |
DC0038 Application Log Content | AN1165 | 1 |
Office Add-in load errors, abnormal loading context, or unsigned add-in warnings |
DC0038 Application Log Content | AN0138 | 1 |
Outlook errors loading or processing custom form templates |
DC0038 Application Log Content | AN0085 | 1 |
Outlook logs indicating failure to load or render HTML page in Home Page view |
DC0038 Application Log Content | AN0502 | 1 |
Outlook rule creation, form load, or homepage redirection |
DC0038 Application Log Content | AN1116 | 1 |
Outlook rule execution failure or abnormal rule execution context |
DC0038 Application Log Content | AN0263 | 1 |
SCCM, Intune logs |
DC0038 Application Log Content | AN0623 | 1 |
Service crash, unhandled exception, or application hang warnings for critical services (e.g., IIS, DNS, SQL Server) |
DC0038 Application Log Content | AN0584 | 1 |
Stored procedure creation, modification, or xp_cmdshell invocation via SQL logs or SQL Server auditing |
DC0029 Script Execution | AN0511 | 1 |
Unexpected spikes in request volume, application-level errors, or thread pool exhaustion in web or API logs |
DC0038 Application Log Content | AN0489 | 1 |
Unexpected web application errors or CMS logs showing modification to index.html, default.aspx, or other public-facing files |
DC0038 Application Log Content | AN0662 | 1 |
Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs |
DC0038 Application Log Content | AN1507 | 1 |
VPN, Citrix, or remote access gateway logs showing external IP addresses |
DC0038 Application Log Content | AN1004 | 1 |
WMI Object Creation Events |
DC0008 WMI Creation | AN0973 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1027.005 Indicator Removal from Tools | stealth | 4 | 0 |
| T1027.011 Fileless Storage | stealth | 1 | 0 |
| T1072 Software Deployment Tools | execution, lateral movement | 4 | 0 |
| T1114 Email Collection | collection | 4 | 3 |
| T1133 External Remote Services | persistence, initial access | 20 | 25 |
| T1137 Office Application Startup | persistence | 9 | 0 |
| T1137.003 Outlook Forms | persistence | 1 | 0 |
| T1137.004 Outlook Home Page | persistence | 0 | 0 |
| T1137.005 Outlook Rules | persistence | 0 | 0 |
| T1137.006 Add-ins | persistence | 4 | 0 |
| T1189 Drive-by Compromise | initial access | 3 | 21 |
| T1203 Exploitation for Client Execution | execution | 35 | 43 |
| T1204 User Execution | execution | 10 | 2 |
| T1491 Defacement | impact | 0 | 0 |
| T1499 Endpoint Denial of Service | impact | 3 | 7 |
| T1499.002 Service Exhaustion Flood | impact | 0 | 2 |
| T1499.003 Application Exhaustion Flood | impact | 0 | 0 |
| T1499.004 Application or System Exploitation | impact | 3 | 2 |
| T1505 Server Software Component | persistence | 1 | 2 |
| T1505.001 SQL Stored Procedures | persistence | 2 | 0 |
| T1505.002 Transport Agent | persistence | 3 | 0 |
| T1547.010 Port Monitors | persistence, privilege escalation | 4 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1133 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 T1499.004 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1203 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 T1203 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1133 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1133 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1133 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1133 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1114 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1133 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1133 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1133 | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1133 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1133 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1203 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1133 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1203 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1499 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1203 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1499.002 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1133 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1203 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1499.002 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1505 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1203 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1203 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1499 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1133 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-23397 | Microsoft Office | T1203 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1133 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1203 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1204 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1133 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1499 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1133 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 T1203 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1203 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1114 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1133 T1203 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1499 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1203 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1203 T1204 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1203 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1499.004 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1203 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-3248 | Langflow Langflow | T1203 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1133 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1203 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1499 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1203 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1203 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1505 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 T1203 | Mapped |