Skip to main content

Core / Ccc / Threats / DEV

Runtime Logs are Read by Unauthorized Entities

CCC.Core.TH09

Unauthorized access to logs may expose valuable information about the system's configuration, operations, and security mechanisms. This could jeopardize system availability through the exposure of vulnerabilities and support the planning of attacks on the service, system, or network. If logs are not adequately sanitized, this may also directly impact the confidentiality of sensitive data.

Related Capabilities

IDTitleDescription
CCC.Core.CP03Access Log PublicationThe service automatically publishes structured, verbose records of activities performed within the scope of the service by external actors.
CCC.Core.CP09Metrics PublicationThe service automatically publishes structured, numeric, time-series data points related to the performance, availability, and health of the service or its child resources.

Related Controls

IDTitleDescription
CCC.Core.CN09Ensure Integrity of Access LogsEnsure that access logs are always recorded to an external location that cannot be manipulated from the context of the service(s) it contains logs for.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1003OS Credential Dumping
MITRE-ATT&CKT1007System Service Discovery
MITRE-ATT&CKT1018Remote System Discovery
MITRE-ATT&CKT1033System Owner/User Discovery
MITRE-ATT&CKT1046Network Service Discovery
MITRE-ATT&CKT1057Process Discovery
MITRE-ATT&CKT1069Permission Groups Discovery
MITRE-ATT&CKT1070Indicator Removal
MITRE-ATT&CKT1082System Information Discovery
MITRE-ATT&CKT1120Peripheral Device Discovery
MITRE-ATT&CKT1124System Time Discovery
MITRE-ATT&CKT1497Virtualization/Sandbox Evasion
MITRE-ATT&CKT1518Software Discovery