kevmap

TechniquesT1486 › AN0605

AN0605 Analytic 0605

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Ransomware encrypts .vmdk, .vmx, .log, or VM config files in VMFS datastores. May rename to .locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through dcui, SSH, or vSphere.</p>
Detects
T1486 Data Encrypted for Impact
Part of
DET0215 Detection of Multi-Platform File Encryption for Impact

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:vmkernelrename .vmdk to .*.locked|datastore write spikeDC0061 File Modification
esxi:shellopenssl|tar|ddDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
FileTypeDetect renames or write patterns involving .vmdk, .vmx, .nvram.
UserContextIdentify shell sessions opened by root or unexpected users outside maintenance window.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped