kevmap

TechniquesT1036.005 › AN0987

AN0987 Analytic 0987

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.</p>
Detects
T1036.005 Match Legitimate Resource Name or Location
Part of
DET0347 Detection Strategy for Masquerading via Legitimate Resource Name or Location

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:vmkernelExecDC0032 Process Creation
esxi:vmkernelmodule loadDC0016 Module Load
esxi:hostdService eventsDC0041 Service Metadata
esxi:hostdtask creation eventsDC0001 Scheduled Job Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
esxi_baseline_file_listKnown good binaries and their expected paths
service_creation_alert_thresholdThreshold for unknown service names or mismatched digital signatures

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-26360Adobe ColdFusionMapped