Techniques › T1572 › AN1486
AN1486 Analytic 1486
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.</p>
- Detects
- T1572 Protocol Tunneling
- Part of
- DET0538 Detection Strategy for Protocol Tunneling accross OS platforms.
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:vpxd | ESXi processes relaying traffic via SSH or unexpected ports | DC0078 Network Traffic Flow |
| esxcli:network | listening sockets bound with non-standard encapsulated protocols | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ESXiServiceProfiles | Baseline allowed services and expected ports for ESXi management. |