Techniques › T1554 › AN0952
AN0952 Analytic 0952
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects unauthorized modification of host binaries, modules, or services within ESXi. Correlates tampered files with subsequent unexpected service behavior or malicious module load attempts.</p>
- Detects
- T1554 Compromise Host Software Binary
- Part of
- DET0336 Detect Compromise of Host Software Binaries
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:hostd | binary or module replacement event | DC0061 File Modification |
| esxi:vmkernel | unexpected module load | DC0016 Module Load |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
MonitoredModules | Define critical ESXi binaries and kernel modules requiring integrity validation |
CorrelationWindow | Adjust timing correlation between binary modification and module/service anomalies |