kevmap

TechniquesT1572 › AN1486

AN1486 Analytic 1486

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.</p>
Detects
T1572 Protocol Tunneling
Part of
DET0538 Detection Strategy for Protocol Tunneling accross OS platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:vpxdESXi processes relaying traffic via SSH or unexpected portsDC0078 Network Traffic Flow
esxcli:networklistening sockets bound with non-standard encapsulated protocolsDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ESXiServiceProfilesBaseline allowed services and expected ports for ESXi management.