kevmap

Log sources › WinEventLog:Sysmon

WinEventLog:Sysmon

Inverted view: what can be detected if this is the log you have. IaaS, Linux, Office Suite, Windows, macOS

24
channels
435
analytics
423
techniques
418
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
EventCode=1 DC0032 Process Creation AN0006 AN0009 AN0012 AN0016 AN0021 AN0024 AN0034 AN0037 AN0040 AN0051 AN0055 AN0061 AN0066 AN0071 AN0080 AN0085 AN0089 AN0091 AN0094 AN0100 AN0105 AN0108 AN0109 AN0113 AN0118 AN0127 AN0130 AN0133 AN0137 AN0147 AN0152 AN0153 AN0165 AN0170 AN0172 AN0176 AN0182 AN0184 AN0185 AN0188 AN0191 AN0204 AN0209 AN0216 AN0219 AN0226 AN0229 AN0236 AN0247 AN0250 AN0254 AN0258 AN0263 AN0265 AN0277 AN0278 AN0286 AN0292 AN0297 AN0302 AN0316 AN0324 AN0327 AN0331 AN0334 AN0341 AN0342 AN0355 AN0360 AN0363 AN0372 AN0375 AN0379 AN0388 AN0396 AN0398 AN0411 AN0423 AN0436 AN0455 AN0462 AN0472 AN0478 AN0502 AN0504 AN0510 AN0511 AN0516 AN0531 AN0535 AN0536 AN0540 AN0558 AN0559 AN0568 AN0576 AN0577 AN0580 AN0581 AN0584 AN0589 AN0590 AN0594 AN0595 AN0599 AN0602 AN0609 AN0616 AN0622 AN0628 AN0630 AN0633 AN0637 AN0641 AN0648 AN0651 AN0655 AN0662 AN0692 AN0694 AN0699 AN0724 AN0728 AN0733 AN0741 AN0750 AN0755 AN0767 AN0778 AN0781 AN0782 AN0786 AN0787 AN0791 AN0797 AN0819 AN0822 AN0838 AN0841 AN0842 AN0846 AN0850 AN0854 AN0856 AN0862 AN0868 AN0872 AN0880 AN0895 AN0903 AN0909 AN0913 AN0919 AN0922 AN0931 AN0932 AN0933 AN0940 AN0941 AN0942 AN0943 AN0954 AN0965 AN0968 AN0980 AN0988 AN0995 AN1012 AN1015 AN1020 AN1029 AN1030 AN1031 AN1032 AN1033 AN1045 AN1048 AN1057 AN1064 AN1075 AN1076 AN1095 AN1108 AN1116 AN1118 AN1133 AN1134 AN1144 AN1165 AN1169 AN1182 AN1185 AN1186 AN1195 AN1198 AN1206 AN1211 AN1212 AN1220 AN1221 AN1229 AN1235 AN1245 AN1246 AN1252 AN1259 AN1280 AN1288 AN1305 AN1308 AN1313 AN1319 AN1323 AN1361 AN1366 AN1381 AN1384 AN1389 AN1393 AN1399 AN1407 AN1410 AN1413 AN1417 AN1419 AN1428 AN1434 AN1436 AN1440 AN1448 AN1452 AN1461 AN1464 AN1465 AN1468 AN1472 AN1480 AN1483 AN1489 AN1495 AN1501 AN1507 AN1516 AN1527 AN1531 AN1536 AN1538 AN1543 AN1557 AN1560 AN1561 AN1564 AN1571 AN1575 AN1583 AN1588 AN1593 AN1604 AN1612 AN1620 AN1621 AN1622 AN2035 AN2038 AN2043 AN2063 264
EventCode=10 DC0035 Process Access AN0016 AN0030 AN0066 AN0074 AN0095 AN0105 AN0126 AN0237 AN0243 AN0271 AN0277 AN0282 AN0287 AN0292 AN0297 AN0327 AN0378 AN0389 AN0405 AN0430 AN0444 AN0478 AN0493 AN0608 AN0619 AN0648 AN0675 AN0687 AN0719 AN0757 AN0767 AN0786 AN0822 AN0838 AN0913 AN0919 AN0932 AN0941 AN0942 AN0965 AN1000 AN1030 AN1035 AN1076 AN1094 AN1095 AN1182 AN1186 AN1193 AN1198 AN1207 AN1212 AN1213 AN1220 AN1253 AN1288 AN1289 AN1324 AN1353 AN1398 AN1399 AN1402 AN1417 AN1443 AN1465 AN1501 AN1535 AN1593 AN1598 AN1641 70
EventCode=11 DC0039 File Creation AN0009 AN0012 AN0021 AN0034 AN0037 AN0040 AN0051 AN0052 AN0055 AN0065 AN0071 AN0072 AN0074 AN0091 AN0094 AN0108 AN0123 AN0130 AN0137 AN0139 AN0162 AN0165 AN0176 AN0178 AN0184 AN0185 AN0188 AN0194 AN0212 AN0229 AN0235 AN0240 AN0247 AN0251 AN0275 AN0278 AN0292 AN0297 AN0320 AN0327 AN0341 AN0342 AN0367 AN0372 AN0375 AN0388 AN0411 AN0428 AN0430 AN0472 AN0484 AN0488 AN0498 AN0510 AN0516 AN0531 AN0540 AN0555 AN0558 AN0568 AN0576 AN0577 AN0580 AN0595 AN0599 AN0602 AN0609 AN0614 AN0616 AN0619 AN0622 AN0629 AN0630 AN0651 AN0655 AN0677 AN0699 AN0712 AN0714 AN0724 AN0747 AN0767 AN0774 AN0782 AN0797 AN0819 AN0831 AN0834 AN0841 AN0854 AN0856 AN0862 AN0872 AN0880 AN0913 AN0932 AN0940 AN0942 AN0949 AN0962 AN0968 AN0983 AN0992 AN1008 AN1028 AN1030 AN1033 AN1040 AN1061 AN1064 AN1070 AN1075 AN1097 AN1108 AN1116 AN1145 AN1153 AN1177 AN1206 AN1207 AN1211 AN1213 AN1216 AN1221 AN1245 AN1246 AN1288 AN1298 AN1303 AN1308 AN1314 AN1319 AN1321 AN1366 AN1381 AN1384 AN1397 AN1407 AN1433 AN1436 AN1458 AN1480 AN1501 AN1511 AN1516 AN1528 AN1531 AN1535 AN1548 AN1551 AN1560 AN1598 AN1610 AN1611 AN2035 AN2063 155
EventCode=12 DC0056 Windows Registry Key Creation AN0153 AN0323 AN0558 AN0622 AN0629 AN0871 AN0886 AN0932 AN1028 AN1186 AN1366 AN2043 11
EventCode=13 DC0063 Windows Registry Key Modification AN0580 1
EventCode=13, 14 DC0063 Windows Registry Key Modification AN0021 AN0074 AN0094 AN0118 AN0123 AN0137 AN0170 AN0235 AN0240 AN0243 AN0251 AN0323 AN0341 AN0360 AN0406 AN0441 AN0520 AN0535 AN0589 AN0622 AN0629 AN0687 AN0694 AN0764 AN0778 AN0781 AN0862 AN0871 AN0880 AN0932 AN0933 AN0975 AN1001 AN1028 AN1030 AN1032 AN1094 AN1116 AN1153 AN1185 AN1221 AN1271 AN1366 AN1369 AN1384 AN1436 AN1452 AN1527 AN1536 AN1551 AN1575 AN1595 AN2043 53
EventCode=15 DC0059 File Metadata AN0094 AN0108 AN0162 AN0176 AN0378 AN0510 AN0555 AN0577 AN0702 AN0712 AN0819 AN0872 AN1097 AN1134 AN1206 AN1211 AN1436 AN1560 AN1626 AN1641 20
EventCode=16 DC0018 Host Status AN0667 0
EventCode=17 DC0048 Named Pipe Metadata AN0513 AN1095 AN1357 3
EventCode=2 DC0061 File Modification AN0137 AN0162 AN0229 AN0235 AN0258 AN0510 AN0602 AN0629 AN0949 AN1245 AN1402 AN1405 AN1611 12
EventCode=23 DC0040 File Deletion AN0392 AN0411 AN0469 AN0520 AN0555 AN0737 AN1216 AN1472 8
EventCode=25 DC0035 Process Access AN1305 1
EventCode=3, 22 DC0082 Network Connection Creation AN0002 AN0030 AN0052 AN0071 AN0075 AN0080 AN0100 AN0109 AN0118 AN0123 AN0130 AN0131 AN0158 AN0165 AN0178 AN0185 AN0204 AN0212 AN0216 AN0219 AN0226 AN0251 AN0274 AN0298 AN0302 AN0320 AN0327 AN0331 AN0345 AN0346 AN0367 AN0379 AN0400 AN0423 AN0436 AN0445 AN0462 AN0485 AN0488 AN0489 AN0498 AN0513 AN0564 AN0568 AN0576 AN0590 AN0596 AN0622 AN0637 AN0651 AN0655 AN0677 AN0702 AN0714 AN0728 AN0741 AN0750 AN0759 AN0785 AN0787 AN0791 AN0797 AN0823 AN0842 AN0862 AN0895 AN0922 AN0927 AN0928 AN0931 AN0932 AN0962 AN0968 AN0969 AN0988 AN1004 AN1020 AN1028 AN1031 AN1057 AN1091 AN1113 AN1118 AN1121 AN1134 AN1140 AN1144 AN1169 AN1178 AN1185 AN1189 AN1207 AN1225 AN1229 AN1254 AN1294 AN1305 AN1308 AN1309 AN1314 AN1331 AN1335 AN1344 AN1366 AN1367 AN1376 AN1381 AN1389 AN1397 AN1398 AN1407 AN1413 AN1434 AN1448 AN1464 AN1468 AN1483 AN1489 AN1496 AN1511 AN1535 AN1548 AN1551 AN1564 AN1571 AN1583 AN1599 AN1610 AN1620 AN2029 AN2035 AN2043 AN2063 130
EventCode=4 DC0041 Service Metadata AN0061 1
EventCode=5 DC0033 Process Termination AN0045 AN1369 2
EventCode=6 DC0079 Driver Load AN0185 AN0384 AN0462 AN0474 AN0629 AN0827 AN0862 AN0882 AN0916 AN1035 AN1061 AN1419 AN1527 AN2038 14
EventCode=7 DC0016 Module Load AN0016 AN0021 AN0048 AN0051 AN0052 AN0071 AN0074 AN0085 AN0108 AN0118 AN0127 AN0184 AN0185 AN0209 AN0219 AN0226 AN0236 AN0237 AN0250 AN0263 AN0287 AN0327 AN0341 AN0388 AN0389 AN0396 AN0400 AN0430 AN0445 AN0462 AN0472 AN0478 AN0488 AN0502 AN0550 AN0558 AN0568 AN0577 AN0578 AN0580 AN0581 AN0583 AN0595 AN0609 AN0622 AN0628 AN0643 AN0733 AN0747 AN0757 AN0759 AN0785 AN0791 AN0814 AN0831 AN0838 AN0862 AN0880 AN0919 AN0968 AN0980 AN1000 AN1028 AN1029 AN1035 AN1048 AN1094 AN1095 AN1133 AN1207 AN1212 AN1220 AN1222 AN1252 AN1288 AN1289 AN1303 AN1305 AN1308 AN1319 AN1323 AN1335 AN1393 AN1398 AN1399 AN1433 AN1458 AN1464 AN1465 AN1480 AN1495 AN1496 AN1535 AN1536 AN1551 AN1588 AN1598 AN1633 AN2063 99
EventCode=8 DC0020 Process Modification AN0277 AN0297 AN0389 AN0822 AN0941 AN1076 AN1289 AN1398 AN1535 AN1551 10
EventCode=9 DC0054 Drive Access AN0275 AN0428 AN0774 3
File creation of suspicious scripts/binaries in temporary directories DC0039 File Creation AN0993 1
Outbound requests with forged tokens/cookies in headers DC0085 Network Traffic Content AN0720 1
Raw disk write access via \\.\PhysicalDrive* or \\.\C: DC0046 Drive Modification AN0384 1
Raw disk writes targeting \\.\PhysicalDrive* or MBR locations DC0046 Drive Modification AN0882 1
Raw write attempts targeting \\.\PhysicalDrive0 or sector 0 (MBR/partition table) DC0046 Drive Modification AN0827 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1001.003 Protocol or Service Impersonationcommand and control20
T1003 OS Credential Dumpingcredential access3718
T1003.001 LSASS Memorycredential access794
T1003.002 Security Account Managercredential access280
T1003.003 NTDScredential access243
T1003.004 LSA Secretscredential access120
T1003.005 Cached Domain Credentialscredential access80
T1005 Data from Local Systemcollection1446
T1006 Direct Volume Accessstealth10
T1008 Fallback Channelscommand and control40
T1010 Application Window Discoverydiscovery10
T1011 Exfiltration Over Other Network Mediumexfiltration04
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1012 Query Registrydiscovery140
T1014 Rootkitstealth10
T1016 System Network Configuration Discoverydiscovery121
T1016.001 Internet Connection Discoverydiscovery00
T1016.002 Wi-Fi Discoverydiscovery00
T1018 Remote System Discoverydiscovery172
T1020 Automated Exfiltrationexfiltration100
T1021 Remote Serviceslateral movement114
T1021.001 Remote Desktop Protocollateral movement162
T1021.002 SMB/Windows Admin Shareslateral movement380
T1021.003 Distributed Component Object Modellateral movement130
T1021.005 VNClateral movement10
T1021.006 Windows Remote Managementlateral movement110
T1021.008 Direct Cloud VM Connectionslateral movement00
T1025 Data from Removable Mediacollection00
T1027 Obfuscated Files or Informationstealth945
T1027.001 Binary Paddingstealth30
T1027.002 Software Packingstealth10
T1027.003 Steganographystealth50
T1027.004 Compile After Deliverystealth60
T1027.005 Indicator Removal from Toolsstealth40
T1027.006 HTML Smugglingstealth00
T1027.007 Dynamic API Resolutionstealth00
T1027.008 Stripped Payloadsstealth00
T1027.009 Embedded Payloadsstealth20
T1027.012 LNK Icon Smugglingstealth00
T1027.013 Encrypted/Encoded Filestealth00
T1027.014 Polymorphic Codestealth00
T1027.015 Compressionstealth00
T1027.016 Junk Code Insertionstealth00
T1027.017 SVG Smugglingstealth00
T1027.018 Invisible Unicodestealth00
T1029 Scheduled Transferexfiltration00
T1030 Data Transfer Size Limitsexfiltration20
T1033 System Owner/User Discoverydiscovery302
T1036 Masqueradingstealth402
T1036.001 Invalid Code Signaturestealth00
T1036.002 Right-to-Left Overridestealth30
T1036.003 Rename Legitimate Utilitiesstealth270
T1036.004 Masquerade Task or Servicestealth30
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1036.007 Double File Extensionstealth30
T1036.008 Masquerade File Typestealth10
T1036.012 Browser Fingerprintstealth00
T1039 Data from Network Shared Drivecollection20
T1041 Exfiltration Over C2 Channelexfiltration512
T1046 Network Service Discoverydiscovery207
T1047 Windows Management Instrumentationexecution522
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1049 System Network Connections Discoverydiscovery91
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.002 Atexecution, persistence, privilege escalation80
T1053.005 Scheduled Taskexecution, persistence, privilege escalation512
T1055 Process Injectionstealth, privilege escalation3719
T1055.001 Dynamic-link Library Injectionstealth, privilege escalation81
T1055.002 Portable Executable Injectionstealth, privilege escalation00
T1055.003 Thread Execution Hijackingstealth, privilege escalation20
T1055.004 Asynchronous Procedure Callstealth, privilege escalation00
T1055.005 Thread Local Storagestealth, privilege escalation00
T1055.011 Extra Window Memory Injectionstealth, privilege escalation10
T1055.012 Process Hollowingstealth, privilege escalation51
T1055.013 Process Doppelgängingstealth, privilege escalation00
T1055.015 ListPlantingstealth, privilege escalation00
T1056 Input Capturecollection, credential access23
T1056.001 Keyloggingcollection, credential access31
T1056.002 GUI Input Capturecollection, credential access30
T1056.003 Web Portal Capturecollection, credential access00
T1056.004 Credential API Hookingcollection, credential access00
T1057 Process Discoverydiscovery80
T1059 Command and Scripting Interpreterexecution95170
T1059.001 PowerShellexecution2201
T1059.003 Windows Command Shellexecution466
T1059.005 Visual Basicexecution290
T1059.006 Pythonexecution130
T1059.007 JavaScriptexecution2914
T1059.010 AutoHotKey & AutoITexecution00
T1059.011 Luaexecution00
T1068 Exploitation for Privilege Escalationprivilege escalation3169
T1070 Indicator Removalstealth203
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1070.005 Network Share Connection Removalstealth40
T1070.006 Timestompstealth60
T1070.007 Clear Network Connection History and Configurationsstealth00
T1070.008 Clear Mailbox Datastealth20
T1070.009 Clear Persistencestealth00
T1070.010 Relocate Malwarestealth00
T1071 Application Layer Protocolcommand and control71
T1071.001 Web Protocolscommand and control4210
T1071.002 File Transfer Protocolscommand and control01
T1071.003 Mail Protocolscommand and control00
T1071.004 DNScommand and control170
T1071.005 Publish/Subscribe Protocolscommand and control00
T1074 Data Stagedcollection20
T1074.001 Local Data Stagingcollection40
T1074.002 Remote Data Stagingcollection00
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1080 Taint Shared Contentlateral movement00
T1082 System Information Discoverydiscovery337
T1083 File and Directory Discoverydiscovery245
T1087 Account Discoverydiscovery166
T1087.001 Local Accountdiscovery131
T1087.002 Domain Accountdiscovery215
T1087.003 Email Accountdiscovery00
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1090.004 Domain Frontingcommand and control10
T1091 Replication Through Removable Medialateral movement, initial access16
T1092 Communication Through Removable Mediacommand and control00
T1095 Non-Application Layer Protocolcommand and control30
T1098 Account Manipulationpersistence, privilege escalation342
T1102 Web Servicecommand and control130
T1102.001 Dead Drop Resolvercommand and control40
T1102.002 Bidirectional Communicationcommand and control40
T1102.003 One-Way Communicationcommand and control20
T1104 Multi-Stage Channelscommand and control00
T1105 Ingress Tool Transfercommand and control8735
T1106 Native APIexecution147
T1110.002 Password Crackingcredential access10
T1111 Multi-Factor Authentication Interceptioncredential access00
T1112 Modify Registrydefense impairment, persistence964
T1113 Screen Capturecollection100
T1114 Email Collectioncollection43
T1114.001 Local Email Collectioncollection10
T1114.002 Remote Email Collectioncollection01
T1115 Clipboard Datacollection80
T1119 Automated Collectioncollection51
T1120 Peripheral Device Discoverydiscovery20
T1123 Audio Capturecollection60
T1124 System Time Discoverydiscovery30
T1125 Video Capturecollection10
T1127 Trusted Developer Utilities Proxy Executionstealth, execution200
T1127.001 MSBuildstealth, execution10
T1127.002 ClickOncestealth, execution00
T1127.003 JamPlusstealth, execution00
T1129 Shared Modulesexecution20
T1132 Data Encodingcommand and control00
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1133 External Remote Servicespersistence, initial access2025
T1134 Access Token Manipulationstealth, privilege escalation40
T1134.001 Token Impersonation/Theftstealth, privilege escalation91
T1134.002 Create Process with Tokenstealth, privilege escalation70
T1135 Network Share Discoverydiscovery70
T1136 Create Accountpersistence310
T1136.001 Local Accountpersistence182
T1136.002 Domain Accountpersistence60
T1137 Office Application Startuppersistence90
T1137.001 Office Template Macrospersistence00
T1137.002 Office Testpersistence20
T1137.003 Outlook Formspersistence10
T1137.004 Outlook Home Pagepersistence00
T1137.005 Outlook Rulespersistence00
T1137.006 Add-inspersistence40
T1140 Deobfuscate/Decode Files or Informationstealth182
T1176 Software Extensionspersistence10
T1176.001 Browser Extensionspersistence20
T1176.002 IDE Extensionspersistence00
T1185 Browser Session Hijackingcollection23
T1187 Forced Authenticationcredential access90
T1189 Drive-by Compromiseinitial access321
T1190 Exploit Public-Facing Applicationinitial access149157
T1195 Supply Chain Compromiseinitial access11
T1195.001 Compromise Software Dependencies and Development Toolsinitial access20
T1195.002 Compromise Software Supply Chaininitial access172
T1195.003 Compromise Hardware Supply Chaininitial access00
T1197 BITS Jobsstealth, persistence, execution160
T1199 Trusted Relationshipinitial access21
T1200 Hardware Additionsinitial access30
T1201 Password Policy Discoverydiscovery60
T1202 Indirect Command Executionstealth409
T1203 Exploitation for Client Executionexecution3543
T1204 User Executionexecution102
T1204.001 Malicious Linkexecution411
T1204.002 Malicious Fileexecution3933
T1204.003 Malicious Imageexecution00
T1204.004 Malicious Copy and Pasteexecution60
T1204.005 Malicious Libraryexecution00
T1205 Traffic Signalingstealth, persistence, command and control00
T1205.001 Port Knockingstealth, persistence, command and control00
T1205.002 Socket Filtersstealth, persistence, command and control00
T1210 Exploitation of Remote Serviceslateral movement154
T1211 Exploitation for Stealthstealth41
T1212 Exploitation for Credential Accesscredential access54
T1213.006 Databasescollection00
T1216 System Script Proxy Executionstealth130
T1216.001 PubPrnstealth20
T1216.002 SyncAppvPublishingServerstealth00
T1217 Browser Information Discoverydiscovery41
T1218 System Binary Proxy Executionstealth1532
T1218.001 Compiled HTML Filestealth60
T1218.002 Control Panelstealth10
T1218.003 CMSTPstealth70
T1218.004 InstallUtilstealth00
T1218.005 Mshtastealth80
T1218.007 Msiexecstealth100
T1218.008 Odbcconfstealth80
T1218.009 Regsvcs/Regasmstealth40
T1218.010 Regsvr32stealth190
T1218.011 Rundll32stealth430
T1218.012 Verclsidstealth00
T1218.013 Mavinjectstealth20
T1218.014 MMCstealth20
T1218.015 Electron Applicationsstealth00
T1219 Remote Access Toolscommand and control61
T1219.001 IDE Tunnelingcommand and control00
T1219.002 Remote Desktop Softwarecommand and control460
T1220 XSL Script Processingstealth50
T1221 Template Injectionstealth23
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.001 Windows Permissionsdefense impairment50
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1480.002 Mutual Exclusionstealth00
T1482 Domain Trust Discoverydiscovery172
T1484 Domain or Tenant Policy Modificationdefense impairment, privilege escalation10
T1484.001 Group Policy Modificationdefense impairment, privilege escalation61
T1484.002 Trust Modificationdefense impairment, privilege escalation20
T1485 Data Destructionimpact206
T1486 Data Encrypted for Impactimpact1615
T1489 Service Stopimpact201
T1490 Inhibit System Recoveryimpact272
T1491 Defacementimpact00
T1491.001 Internal Defacementimpact40
T1491.002 External Defacementimpact01
T1495 Firmware Corruptionimpact12
T1496 Resource Hijackingimpact1319
T1496.001 Compute Hijackingimpact00
T1496.002 Bandwidth Hijackingimpact00
T1497 Virtualization/Sandbox Evasionstealth, discovery04
T1497.001 System Checksstealth, discovery30
T1497.002 User Activity Based Checksstealth, discovery00
T1497.003 Time Based Checksstealth, discovery00
T1498 Network Denial of Serviceimpact38
T1498.001 Direct Network Floodimpact01
T1498.002 Reflection Amplificationimpact00
T1499 Endpoint Denial of Serviceimpact37
T1499.001 OS Exhaustion Floodimpact10
T1499.002 Service Exhaustion Floodimpact02
T1499.003 Application Exhaustion Floodimpact00
T1499.004 Application or System Exploitationimpact32
T1505 Server Software Componentpersistence12
T1505.001 SQL Stored Procedurespersistence20
T1505.002 Transport Agentpersistence30
T1505.003 Web Shellpersistence3526
T1505.004 IIS Componentspersistence50
T1505.005 Terminal Services DLLpersistence10
T1518.001 Security Software Discoverydiscovery90
T1518.002 Backup Software Discoverydiscovery00
T1529 System Shutdown/Rebootimpact80
T1531 Account Access Removalimpact91
T1534 Internal Spearphishinglateral movement00
T1539 Steal Web Session Cookiecredential access20
T1542 Pre-OS Bootstealth, persistence00
T1542.001 System Firmwarestealth, persistence20
T1542.002 Component Firmwarestealth, persistence00
T1542.003 Bootkitstealth, persistence10
T1543 Create or Modify System Processpersistence, privilege escalation99
T1543.003 Windows Servicepersistence, privilege escalation470
T1546 Event Triggered Executionprivilege escalation, persistence100
T1546.001 Change Default File Associationprivilege escalation, persistence50
T1546.002 Screensaverprivilege escalation, persistence40
T1546.003 Windows Management Instrumentation Event Subscriptionprivilege escalation, persistence120
T1546.007 Netsh Helper DLLprivilege escalation, persistence40
T1546.008 Accessibility Featuresprivilege escalation, persistence60
T1546.009 AppCert DLLsprivilege escalation, persistence20
T1546.010 AppInit DLLsprivilege escalation, persistence10
T1546.011 Application Shimmingprivilege escalation, persistence60
T1546.012 Image File Execution Options Injectionprivilege escalation, persistence20
T1546.013 PowerShell Profileprivilege escalation, persistence30
T1546.015 Component Object Model Hijackingprivilege escalation, persistence90
T1546.016 Installer Packagesprivilege escalation, persistence00
T1547 Boot or Logon Autostart Executionpersistence, privilege escalation71
T1547.001 Registry Run Keys / Startup Folderpersistence, privilege escalation391
T1547.002 Authentication Packagepersistence, privilege escalation10
T1547.003 Time Providerspersistence, privilege escalation10
T1547.004 Winlogon Helper DLLpersistence, privilege escalation40
T1547.005 Security Support Providerpersistence, privilege escalation10
T1547.008 LSASS Driverpersistence, privilege escalation10
T1547.009 Shortcut Modificationpersistence, privilege escalation41
T1547.010 Port Monitorspersistence, privilege escalation40
T1547.012 Print Processorspersistence, privilege escalation00
T1547.014 Active Setuppersistence, privilege escalation10
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1548.002 Bypass User Account Controlprivilege escalation561
T1550 Use Alternate Authentication Materiallateral movement50
T1550.002 Pass the Hashlateral movement64
T1550.003 Pass the Ticketlateral movement70
T1552 Unsecured Credentialscredential access134
T1552.001 Credentials In Filescredential access243
T1552.002 Credentials in Registrycredential access50
T1552.004 Private Keyscredential access71
T1552.006 Group Policy Preferencescredential access60
T1553 Subvert Trust Controlsdefense impairment40
T1553.002 Code Signingdefense impairment10
T1553.003 SIP and Trust Provider Hijackingdefense impairment20
T1553.004 Install Root Certificatedefense impairment100
T1553.005 Mark-of-the-Web Bypassdefense impairment62
T1554 Compromise Host Software Binarypersistence60
T1555 Credentials from Password Storescredential access89
T1555.003 Credentials from Web Browserscredential access80
T1555.004 Windows Credential Managercredential access40
T1555.005 Password Managerscredential access10
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.001 Domain Controller Authenticationdefense impairment, persistence, credential access00
T1556.002 Password Filter DLLdefense impairment, persistence, credential access30
T1556.005 Reversible Encryptiondefense impairment, persistence, credential access00
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1556.008 Network Provider DLLdefense impairment, persistence, credential access00
T1557 Adversary-in-the-Middlecredential access, collection104
T1557.002 ARP Cache Poisoningcredential access, collection00
T1558 Steal or Forge Kerberos Ticketscredential access63
T1558.001 Golden Ticketcredential access10
T1558.002 Silver Ticketcredential access10
T1558.003 Kerberoastingcredential access180
T1558.004 AS-REP Roastingcredential access00
T1559 Inter-Process Communicationexecution10
T1559.001 Component Object Modelexecution40
T1559.002 Dynamic Data Exchangeexecution10
T1560 Archive Collected Datacollection40
T1560.001 Archive via Utilitycollection172
T1560.002 Archive via Librarycollection00
T1560.003 Archive via Custom Methodcollection00
T1561 Disk Wipeimpact00
T1561.001 Disk Content Wipeimpact10
T1561.002 Disk Structure Wipeimpact10
T1563 Remote Service Session Hijackinglateral movement00
T1563.002 RDP Hijackinglateral movement20
T1564 Hide Artifactsstealth100
T1564.001 Hidden Files and Directoriesstealth90
T1564.002 Hidden Usersstealth40
T1564.003 Hidden Windowstealth80
T1564.004 NTFS File Attributesstealth230
T1564.005 Hidden File Systemstealth00
T1564.006 Run Virtual Instancestealth20
T1564.007 VBA Stompingstealth00
T1564.010 Process Argument Spoofingstealth00
T1564.011 Ignore Process Interruptsstealth00
T1564.012 File/Path Exclusionsstealth00
T1565 Data Manipulationimpact32
T1565.001 Stored Data Manipulationimpact62
T1565.002 Transmitted Data Manipulationimpact20
T1565.003 Runtime Data Manipulationimpact00
T1566 Phishinginitial access146
T1566.001 Spearphishing Attachmentinitial access247
T1566.002 Spearphishing Linkinitial access45
T1566.003 Spearphishing via Serviceinitial access00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1568 Dynamic Resolutioncommand and control20
T1568.001 Fast Flux DNScommand and control00
T1568.002 Domain Generation Algorithmscommand and control20
T1568.003 DNS Calculationcommand and control00
T1569 System Servicesexecution40
T1569.002 Service Executionexecution431
T1570 Lateral Tool Transferlateral movement61
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00
T1574 Hijack Execution Flowstealth, execution816
T1574.001 DLLstealth, execution930
T1574.005 Executable Installer File Permissions Weaknessstealth, execution20
T1574.007 Path Interception by PATH Environment Variablestealth, execution20
T1574.008 Path Interception by Search Order Hijackingstealth, execution20
T1574.009 Path Interception by Unquoted Pathstealth, execution00
T1574.010 Services File Permissions Weaknessstealth, execution00
T1574.011 Services Registry Permissions Weaknessstealth, execution110
T1574.012 COR_PROFILERstealth, execution20
T1574.013 KernelCallbackTablestealth, execution00
T1574.014 AppDomainManagerstealth, execution00
T1606 Forge Web Credentialscredential access10
T1606.001 Web Cookiescredential access00
T1611 Escape to Hostprivilege escalation23
T1614.001 System Language Discoverydiscovery20
T1615 Group Policy Discoverydiscovery50
T1620 Reflective Code Loadingstealth30
T1622 Debugger Evasionstealth, discovery12
T1652 Device Driver Discoverydiscovery00
T1657 Financial Theftimpact00
T1659 Content Injectioninitial access, command and control00
T1667 Email Bombingimpact00
T1668 Exclusive Controlpersistence00
T1678 Delay Executionstealth00
T1680 Local Storage Discoverydiscovery00
T1684 Social Engineeringstealth00
T1685 Disable or Modify Toolsdefense impairment1640
T1685.001 Disable or Modify Windows Event Logdefense impairment280
T1685.003 Modify or Spoof Tool UIdefense impairment00
T1685.005 Clear Windows Event Logsdefense impairment80
T1686 Disable or Modify System Firewalldefense impairment70
T1686.003 Windows Host Firewalldefense impairment200
T1687 Exploitation for Defense Impairmentdefense impairment00
T1688 Safe Mode Bootdefense impairment00
T1689 Downgrade Attackdefense impairment10
T1690 Prevent Command History Loggingdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2007-5659Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-0655Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-2992Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-1862Adobe Acrobat and Reader, Flash Player T1204.002 Mapped
CVE-2009-3953Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-3960Adobe BlazeDS T1190 T1486 Mapped
CVE-2009-4324Adobe Acrobat and Reader T1071.001 T1204.002 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 T1189 Mapped
CVE-2010-1297Adobe Flash Player T1105 T1189 T1204.002 Mapped
CVE-2010-2861Adobe ColdFusion T1105 T1119 T1190 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 T1059 T1204.002 Mapped
CVE-2011-0611Adobe Flash Player T1105 T1204.002 Mapped
CVE-2011-2462Adobe Reader and Acrobat T1204.002 Mapped
CVE-2012-0754Adobe Flash Player T1105 T1204.002 Mapped
CVE-2012-0767Adobe Flash Player T1098 T1114.002 T1185 T1204.001 Mapped
CVE-2012-1535Adobe Flash Player T1105 T1204.002 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0625Adobe ColdFusion T1190 Mapped
CVE-2013-0629Adobe ColdFusion T1005 T1190 T1202 Mapped
CVE-2013-0631Adobe ColdFusion T1190 Mapped
CVE-2013-0632Adobe ColdFusion T1190 Mapped
CVE-2013-0640Adobe Reader and Acrobat T1566.001 Mapped
CVE-2013-0641Adobe Reader T1048 T1105 T1204.002 Mapped
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2014-0496Adobe Reader and Acrobat T1204.002 Mapped
CVE-2014-0546Adobe Reader and Acrobat T1068 T1497 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1133 T1190 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1133 T1190 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 T1204.002 T1499.004 Mapped
CVE-2015-3113Adobe Flash Player T1071.001 T1204.002 T1497 T1622 Mapped
CVE-2015-5119Adobe Flash Player T1055.001 T1059.007 T1071.001 T1105 T1203 T1204.001 T1566.002 Mapped
CVE-2015-7645Adobe Flash Player T1204.002 Mapped
CVE-2015-8651Adobe Flash Player T1105 T1189 T1486 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 T1204.002 Mapped
CVE-2016-10033PHP PHPMailer T1190 Mapped
CVE-2016-1010Adobe Flash Player and AIR T1574 Mapped
CVE-2016-1019Adobe Flash Player T1105 T1189 T1486 Mapped
CVE-2016-4117Adobe Flash Player T1105 T1204.002 Mapped
CVE-2016-4437Apache Shiro T1059 T1190 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-11292Adobe Flash Player T1005 T1105 T1204.002 T1566.001 Mapped
CVE-2017-11882Microsoft Office T1059 T1566.001 Mapped
CVE-2017-12637SAP NetWeaver T1083 T1190 T1555 Mapped
CVE-2017-5638Apache Struts T1005 T1059 T1190 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 T1059 T1574 Mapped
CVE-2017-9805Apache Struts T1059 T1190 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1059 T1190 T1496 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 T1202 Mapped
CVE-2018-11776Apache Struts T1059 T1190 T1496 Mapped
CVE-2018-13379Fortinet FortiOS T1190 Mapped
CVE-2018-15961Adobe ColdFusion T1190 T1491.002 Mapped
CVE-2018-15982Adobe Flash Player T1105 T1204.002 Mapped
CVE-2018-4878Adobe Flash Player T1041 T1204.002 T1219 Mapped
CVE-2018-4939Adobe ColdFusion T1133 T1190 T1203 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 T1204.002 Mapped
CVE-2018-6789Exim Exim T1059 T1190 Mapped
CVE-2018-7600Drupal Drupal Core T1059 T1190 T1485 T1496 Mapped
CVE-2019-0211Apache HTTP Server T1068 Mapped
CVE-2019-0604Microsoft SharePoint T1003 T1041 T1190 T1505.003 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1133 T1498 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1059 T1083 T1133 T1552.001 Mapped
CVE-2019-11580Atlassian Crowd and Crowd Data Center T1059 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1003 T1005 T1046 T1059 T1078 T1190 T1486 Mapped
CVE-2019-13608Citrix StoreFront Server T1003 T1005 T1046 T1059 T1078 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 T1082 T1190 Mapped
CVE-2019-17558Apache Solr T1059 T1190 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 T1190 T1496 T1505.003 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1059 T1083 T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 T1133 T1202 Mapped
CVE-2019-3398Atlassian Confluence Server and Data Center T1059 T1202 Mapped
CVE-2019-5591Fortinet FortiOS T1005 T1133 T1557 Mapped
CVE-2020-0069MediaTek Multiple Chipsets T1068 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 T1190 T1505.003 Mapped
CVE-2020-0787Microsoft Windows T1059 T1068 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1068 T1087.002 T1133 T1486 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1059 T1190 Mapped
CVE-2020-17530Apache Struts T1059 T1190 Mapped
CVE-2020-25506D-Link DNS-320 Device T1059 T1133 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1059 T1190 Mapped
CVE-2020-29574Sophos CyberoamOS T1055 T1059 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 T1202 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 T1204.001 T1217 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 T1574 Mapped
CVE-2020-5902F5 BIG-IP T1003 T1005 T1059 T1070.004 T1133 T1190 T1552 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1556 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1059 T1133 T1496 Mapped
CVE-2020-8657EyesOfNetwork EyesOfNetwork T1106 Mapped
CVE-2021-1497Cisco HyperFlex HX T1059 T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1059 T1133 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1059 T1078 Mapped
CVE-2021-21017Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-21148Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-21166Google Chromium T1059.007 T1203 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 T1203 Mapped
CVE-2021-21972VMware vCenter Server T1059 T1190 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 T1190 Mapped
CVE-2021-21975VMware vRealize Operations Manager API T1190 Mapped
CVE-2021-22005VMware vCenter Server T1059 T1190 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 T1190 Mapped
CVE-2021-22204Perl Exiftool T1059 T1190 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1059 T1190 T1496 T1498 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1003 T1059 T1190 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1059 T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1059.003 T1078 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1059 T1068 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1059 T1090 T1133 T1190 T1485 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1059 T1496 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 T1190 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 T1090 T1133 T1505.003 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 T1505.003 Mapped
CVE-2021-26858Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-27065Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27101Accellion FTA T1005 T1059 Mapped
CVE-2021-27102Accellion FTA T1005 T1059 T1190 Mapped
CVE-2021-27103Accellion FTA T1005 T1190 Mapped
CVE-2021-27104Accellion FTA T1005 T1059 T1190 Mapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software T1190 T1505.003 Mapped
CVE-2021-28550Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 T1068 T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 T1203 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1059 T1190 Mapped
CVE-2021-31207Microsoft Exchange Server T1548.002 T1565 Mapped
CVE-2021-3129Laravel Ignition T1059 T1190 Mapped
CVE-2021-32030ASUS Routers T1068 T1098 Mapped
CVE-2021-33739Microsoft Windows T1068 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 T1053.005 T1136 T1190 T1486 Mapped
CVE-2021-34523Microsoft Exchange Server T1190 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1059 T1071.001 T1105 T1190 T1496 T1499 T1569.002 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1059 T1190 Mapped
CVE-2021-36380Sunhillo SureLine T1190 Mapped
CVE-2021-36934Microsoft Windows T1068 T1078 Mapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP) T1190 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-39144XStream XStream T1190 T1203 Mapped
CVE-2021-39226Grafana Labs Grafana T1190 T1485 Mapped
CVE-2021-4034Red Hat Polkit T1068 Mapped
CVE-2021-40449Microsoft Windows T1016 T1027 T1059.003 T1068 T1071.001 T1082 T1566 T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1003 T1003.003 T1027 T1047 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 Mapped
CVE-2021-40655D-Link DIR-605 Router T1190 Mapped
CVE-2021-41379Microsoft Windows T1068 T1078 Mapped
CVE-2021-41773Apache HTTP Server T1059 T1210 Mapped
CVE-2021-42013Apache HTTP Server T1059 T1210 Mapped
CVE-2021-42237Sitecore XP T1059 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1059 T1486 Mapped
CVE-2021-42321Microsoft Exchange T1059 T1078 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1003 T1003.003 T1027 T1047 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 Mapped
CVE-2021-44228Apache Log4j2 T1190 T1486 T1496 T1505.003 Mapped
CVE-2021-44515Zoho Desktop Central T1003 T1087 T1105 T1190 Mapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1190 T1195.002 Mapped
CVE-2021-45046Apache Log4j2 T1059 T1486 Mapped
CVE-2021-45382D-Link Multiple Routers T1059 T1070 T1071 T1190 T1499.002 T1543 Mapped
CVE-2022-0028Palo Alto Networks PAN-OS T1190 T1498 Mapped
CVE-2022-1040Sophos Firewall T1059 T1078 T1190 T1557 T1574 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1133 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1190 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1068 T1190 Mapped
CVE-2022-20821Cisco IOS XR T1190 Mapped
CVE-2022-21919Microsoft Windows T1068 T1078 Mapped
CVE-2022-21971Microsoft Windows T1059 T1204.001 Mapped
CVE-2022-21999Microsoft Windows T1059 T1068 T1078 T1136.001 T1211 Mapped
CVE-2022-22047Microsoft Windows T1059 T1068 T1078 T1547.001 Mapped
CVE-2022-22718Microsoft Windows T1068 T1078 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1059 T1190 T1486 Mapped
CVE-2022-22948VMware vCenter Server T1068 T1078 T1212 Mapped
CVE-2022-22954VMware Workspace ONE Access and Identity Manager T1221 T1505.003 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 T1190 T1505.003 Mapped
CVE-2022-22965VMware Spring Framework T1059 T1190 Mapped
CVE-2022-23131Zabbix Frontend T1059 T1078 T1190 T1548 Mapped
CVE-2022-23748Audinate Dante Discovery T1059 T1203 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 T1190 Mapped
CVE-2022-24521Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 T1185 T1204.001 Mapped
CVE-2022-26134Atlassian Confluence Server/Data Center T1190 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26258D-Link DIR-820L T1059 T1190 T1499.002 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 T1048 T1059 T1078 T1190 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 T1048 T1059 T1190 Mapped
CVE-2022-26904Microsoft Windows T1068 T1078 Mapped
CVE-2022-28810Zoho ManageEngine T1190 Mapped
CVE-2022-29303SolarView Compact T1059 T1496 T1505 Mapped
CVE-2022-29464WSO2 Multiple Products T1190 T1202 T1496 Mapped
CVE-2022-30190Microsoft Windows T1105 T1204.002 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 T1574 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-34713Microsoft Windows T1059 T1204.002 T1566 Mapped
CVE-2022-35405Zoho ManageEngine T1059 Mapped
CVE-2022-35914Teclib GLPI T1059 T1190 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1059 T1190 Mapped
CVE-2022-37969Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-39197Fortra Cobalt Strike T1059 T1190 Mapped
CVE-2022-40684Fortinet Multiple Products T1190 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1068 T1566.001 Mapped
CVE-2022-41073Microsoft Windows T1068 T1078 T1574 Mapped
CVE-2022-41082Microsoft Exchange Server T1059.001 T1078 T1087 T1482 T1505.003 T1567 Mapped
CVE-2022-41125Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-41128Microsoft Windows T1070 T1203 T1566 Mapped
CVE-2022-41328Fortinet FortiOS T1049 T1565.001 T1574 Mapped
CVE-2022-42475Fortinet FortiOS T1071.001 T1190 T1574 T1622 Mapped
CVE-2022-42948Fortra Cobalt Strike T1059 T1190 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 T1203 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 T1190 Mapped
CVE-2022-47966Zoho ManageEngine T1068 T1136.001 T1190 Mapped
CVE-2023-0386Linux Kernel T1055.012 T1543 Stale
CVE-2023-0669Fortra GoAnywhere MFT T1190 T1210 T1486 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 T1070 T1106 T1496 T1498 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1059 T1078 T1499 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1059 T1068 T1078 T1505.003 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1136 T1190 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 T1133 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1059 T1068 T1078 Mapped
CVE-2023-20867VMware Tools T1059 T1078 T1105 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1059 T1190 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 T1204.002 Mapped
CVE-2023-21674Microsoft Windows T1068 T1078 Mapped
CVE-2023-21715Microsoft Office T1204.002 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059 T1059.007 T1078 T1136 T1190 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1033 T1105 T1190 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1221 T1496 Mapped
CVE-2023-22952SugarCRM Multiple Products T1021.001 T1059 T1070.004 T1078 T1083 T1190 T1482 T1505.003 Stale
CVE-2023-23397Microsoft Office T1078 T1203 T1550.002 Mapped
CVE-2023-2533PaperCut NG/MF T1059 T1547 T1566.002 Mapped
CVE-2023-26359Adobe ColdFusion T1059 T1190 Mapped
CVE-2023-26360Adobe ColdFusion T1003.001 T1036.005 T1046 T1059.007 T1071.001 T1105 T1190 T1484.001 T1505.003 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 T1204.002 Mapped
CVE-2023-27350PaperCut MF/NG T1059 T1105 T1190 Mapped
CVE-2023-27524Apache Superset T1078 T1190 Mapped
CVE-2023-27532Veeam Backup & Replication T1059.003 T1087 T1087.001 T1133 T1486 T1555 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1136 T1190 T1574 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1068 T1078 Mapped
CVE-2023-28252Microsoft Windows T1003 T1021 T1059 T1068 T1078 T1136 T1486 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 T1059 T1105 T1566.001 Mapped
CVE-2023-29298Adobe ColdFusion T1190 Mapped
CVE-2023-29300Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-29492Novi Survey Novi Survey T1190 Mapped
CVE-2023-32315Ignite Realtime Openfire T1087.002 T1202 T1496 T1505.003 Mapped
CVE-2023-33246Apache RocketMQ T1059 T1190 Mapped
CVE-2023-33538TP-Link Multiple Routers T1059 T1068 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1055 T1059 T1185 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 T1059 T1082 T1105 T1136 T1190 T1531 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1136 T1190 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1087.002 T1105 T1190 T1574 Mapped
CVE-2023-36844Juniper Junos OS T1190 T1203 Mapped
CVE-2023-36845Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36846Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36847Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36851Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36884Microsoft Windows T1005 T1204.002 T1486 T1489 T1490 T1553.005 T1566 Stale
CVE-2023-38035Ivanti Sentry T1018 T1046 T1059 T1071.001 T1105 T1190 T1496 T1571 Mapped
CVE-2023-38203Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-38205Adobe ColdFusion T1190 Mapped
CVE-2023-38831RARLAB WinRAR T1005 T1041 T1053 T1105 T1112 T1204 T1486 Mapped
CVE-2023-38950ZKTeco BioTime T1005 T1190 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1078 T1133 Mapped
CVE-2023-40044Progress WS_FTP Server T1059 T1071.002 T1202 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1059 T1078 Mapped
CVE-2023-42793JetBrains TeamCity T1059.003 T1190 Mapped
CVE-2023-43770Roundcube Webmail T1059 T1082 T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1068 T1543 T1548 Mapped
CVE-2023-44487IETF HTTP/2 T1190 T1499 Mapped
CVE-2023-46604Apache ActiveMQ T1053.005 T1190 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 T1190 T1505.003 T1555 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 T1496 T1498 Mapped
CVE-2023-48365Qlik Sense T1059 T1133 T1190 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1059 T1105 T1190 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 T1190 T1552 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 T1134.001 T1574 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 T1496 T1498 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 T1574 Mapped
CVE-2023-5631Roundcube Webmail T1041 T1059.007 T1204.001 Mapped
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway T1055 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 T1574 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 T1574 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1059 T1105 T1190 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 T1190 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 T1203 T1498 Mapped
CVE-2024-11182MDaemon Email Server T1059 T1566 T1567 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1059 T1068 Mapped
CVE-2024-12987DrayTek Vigor Routers T1059 T1068 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 T1190 T1550.002 T1558 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 T1190 T1550.002 T1558 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 T1190 T1550.002 T1558 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1190 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 T1078 Mapped
CVE-2024-20399Cisco NX-OS T1059 T1078 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1106 T1552 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1059 T1190 Mapped
CVE-2024-21413Microsoft Office Outlook T1059 T1566.002 Mapped
CVE-2024-21762Fortinet FortiOS T1190 T1547.009 T1574 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1059 T1190 T1505.003 T1552 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 T1190 T1505.003 T1555 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 T1082 T1105 T1221 T1496 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1003.003 T1005 T1202 Mapped
CVE-2024-26169Microsoft Windows T1059 T1112 T1203 Mapped
CVE-2024-27198JetBrains TeamCity T1059 T1190 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1114 T1566.002 Mapped
CVE-2024-29059Microsoft .NET Framework T1059 T1068 Mapped
CVE-2024-30051Microsoft DWM Core Library T1068 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 T1059 T1190 Mapped
CVE-2024-37085VMware ESXi T1068 T1078 Mapped
CVE-2024-38080Microsoft Windows T1068 T1204.002 Mapped
CVE-2024-38112Microsoft Windows T1189 T1204.001 Mapped
CVE-2024-38475Apache HTTP Server T1005 T1059 T1190 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1011 T1055 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1011 T1055 Mapped
CVE-2024-41710Mitel SIP Phones T1059 T1068 Mapped
CVE-2024-41713Mitel MiCollab T1005 T1068 Mapped
CVE-2024-42009Roundcube Webmail T1056 T1114 T1566.002 Mapped
CVE-2024-4358Progress Telerik Report Server T1190 Mapped
CVE-2024-45195Apache OFBiz T1059 T1133 T1203 T1498.001 Mapped
CVE-2024-4577PHP Group PHP T1003 T1003.001 T1033 T1041 T1053 T1059 T1068 T1071.001 T1112 T1190 T1543 T1570 Mapped
CVE-2024-4671Google Chromium T1059 T1189 Mapped
CVE-2024-4761Google Chromium V8 T1059 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1003 T1005 T1190 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 T1190 Mapped
CVE-2024-4885Progress WhatsUp Gold T1059 T1068 Mapped
CVE-2024-49035Microsoft Partner Center T1068 T1195 Mapped
CVE-2024-4947Google Chromium V8 T1059 T1189 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 T1071.001 T1105 T1195.002 Mapped
CVE-2024-50302Linux Kernel T1005 T1011 T1091 Mapped
CVE-2024-50603Aviatrix Controllers T1055 T1059 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 Mapped
CVE-2024-5274Google Chromium V8 T1189 T1203 Mapped
CVE-2024-53104Linux Kernel T1059 T1068 T1091 Mapped
CVE-2024-53150Linux Kernel T1005 T1011 T1091 Mapped
CVE-2024-53197Linux Kernel T1059 T1068 T1091 Mapped
CVE-2024-53704SonicWall SonicOS T1021.001 T1083 T1199 T1212 Mapped
CVE-2024-54085AMI MegaRAC SPx T1068 T1210 T1495 T1499 Mapped
CVE-2024-55550Mitel MiCollab T1005 T1041 T1190 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 T1068 T1078 T1555 Mapped
CVE-2024-56145Craft CMS Craft CMS T1055 T1059 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1003 T1059 T1190 T1552.001 T1552.004 Mapped
CVE-2024-57968Advantive VeraCore T1059 T1078 Mapped
CVE-2024-58136Yiiframework Yii T1055 T1059 Mapped
CVE-2024-6047GeoVision Multiple Devices T1055 T1059 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1055 T1190 T1565.001 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 T1068 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1003 T1018 T1046 T1055 T1190 Mapped
CVE-2025-04117-Zip 7-Zip T1553.005 T1566.001 Mapped
CVE-2025-0994Trimble Cityworks T1059 T1068 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1055 T1190 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1059 T1068 Mapped
CVE-2025-20281Cisco Identity Services Engine T1059 T1106 Mapped
CVE-2025-20337Cisco Identity Services Engine T1059 T1106 Mapped
CVE-2025-21333Microsoft Windows T1003 T1068 Mapped
CVE-2025-21334Microsoft Windows T1003 T1068 Mapped
CVE-2025-21335Microsoft Windows T1003 T1068 Mapped
CVE-2025-21391Microsoft Windows T1068 T1485 T1490 Mapped
CVE-2025-21418Microsoft Windows T1005 T1055 T1068 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1055 T1495 Mapped
CVE-2025-21590Juniper Junos OS T1059 T1068 Mapped
CVE-2025-22224VMware ESXi and Workstation T1055 T1611 Mapped
CVE-2025-22225VMware ESXi T1068 T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 T1611 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1059 T1190 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1059 T1190 Mapped
CVE-2025-24016Wazuh Wazuh Server T1059 T1078 T1203 Mapped
CVE-2025-24054Microsoft Windows T1555 T1566 Mapped
CVE-2025-24085Apple Multiple Products T1059 T1068 Mapped
CVE-2025-24201Apple Multiple Products T1059 T1189 Mapped
CVE-2025-24985Microsoft Windows T1059 T1091 Mapped
CVE-2025-24991Microsoft Windows T1005 T1091 Mapped
CVE-2025-24993Microsoft Windows T1055 T1068 T1203 T1204 T1565 Mapped
CVE-2025-25181Advantive VeraCore T1055 T1068 T1485 Mapped
CVE-2025-25257Fortinet FortiWeb T1055 T1068 T1190 T1485 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1059 T1203 Mapped
CVE-2025-27363FreeType FreeType T1204.002 T1499.004 T1574 Mapped
CVE-2025-2783Google Chromium Mojo T1203 T1497 T1548 Mapped
CVE-2025-30397Microsoft Windows T1059 T1203 Mapped
CVE-2025-30400Microsoft Windows T1068 T1112 Mapped
CVE-2025-30406Gladinet CentreStack T1059 T1203 Mapped
CVE-2025-31161CrushFTP CrushFTP T1059 T1078 T1136 Mapped
CVE-2025-31200Apple Multiple Products T1059 T1105 T1106 T1203 T1557 Stale
CVE-2025-31201Apple Multiple Products T1059 T1105 T1106 T1203 T1557 Stale
CVE-2025-31324SAP NetWeaver T1055 T1059 T1505.003 Mapped
CVE-2025-32433Erlang Erlang/OTP T1059 Mapped
CVE-2025-3248Langflow Langflow T1059 T1203 Mapped
CVE-2025-32701Microsoft Windows T1003.001 T1059 T1068 T1543 Mapped
CVE-2025-32706Microsoft Windows T1003.001 T1059 T1068 T1543 Mapped
CVE-2025-32709Microsoft Windows T1003 T1059 T1068 T1543 Mapped
CVE-2025-32756Fortinet Multiple Products T1003 T1041 T1046 T1059 T1070.004 T1133 Mapped
CVE-2025-33053Microsoft Windows T1041 T1056.001 T1059 T1543 T1566.001 Mapped
CVE-2025-34028Commvault Command Center T1059.007 T1190 Mapped
CVE-2025-35939Craft CMS Craft CMS T1059 T1190 T1505.003 Mapped
CVE-2025-3928Commvault Web Server T1059 T1505.003 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1059 T1203 Mapped
CVE-2025-42599Qualitia Active! Mail T1059 T1190 T1499 Mapped
CVE-2025-42999SAP NetWeaver T1059 T1190 T1203 T1505.003 Mapped
CVE-2025-43200Apple Multiple Products T1005 T1105 T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 T1203 T1505.003 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 T1543 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1059 T1068 T1496 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1059 T1068 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-49704Microsoft SharePoint T1059.003 T1190 Mapped
CVE-2025-49706Microsoft SharePoint T1059.003 T1190 T1505 Mapped
CVE-2025-53770Microsoft SharePoint T1059 T1190 Mapped
CVE-2025-5419Google Chromium V8 T1189 T1203 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 T1068 T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1190 T1555 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1059 T1203 T1498 Mapped
CVE-2025-6554Google Chromium V8 T1059 T1189 T1203 Mapped
CVE-2025-6558Google Chromium T1189 T1203 T1497 Mapped