kevmap

TechniquesT1554 › AN0952

AN0952 Analytic 0952

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects unauthorized modification of host binaries, modules, or services within ESXi. Correlates tampered files with subsequent unexpected service behavior or malicious module load attempts.</p>
Detects
T1554 Compromise Host Software Binary
Part of
DET0336 Detect Compromise of Host Software Binaries

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:hostdbinary or module replacement eventDC0061 File Modification
esxi:vmkernelunexpected module loadDC0016 Module Load

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MonitoredModulesDefine critical ESXi binaries and kernel modules requiring integrity validation
CorrelationWindowAdjust timing correlation between binary modification and module/service anomalies