kevmap

TechniquesT1090 › AN1232

AN1232 Analytic 1232

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Direct use of nc, socat, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems.</p>
Detects
T1090 Proxy
Part of
DET0445 Detection of Proxy Infrastructure Setup and Traffic Bridging

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:shellNoneDC0064 Command Execution
esxi:vmkernelNoneDC0078 Network Traffic Flow
NSM:Flowconn.logDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CLICommandCustom proxy or port forwarding scripts executed from ESXi shell.
DestinationIPUnusual outbound connections from ESXi host, particularly to internet.
UserContextRoot or elevated users initiating unexpected tunnels.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped