kevmap

TechniquesT1001.001 › AN0033

AN0033 Analytic 0033

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Anomalous traffic from ESXi host management daemons (like hostd or vpxa) embedding non-standard payloads in management protocols (e.g., HTTPS) or beaconing behavior.</p>
Detects
T1001.001 Junk Data
Part of
DET0011 Detecting Junk Data in C2 Channels via Behavioral Analysis

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:vmkernelNetwork activityDC0085 Network Traffic Content
esxi:hostdSystem service interactionsDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TLSFingerprintMismatchDetects mismatched TLS client behavior vs expected for hostd/vpxa.
UnusualDestinationPortsHighlight traffic from ESXi hosts to uncommon ports outside vCenter ranges.