{"id":"T1505.006","name":"vSphere Installation Bundles","url":"https://attack.mitre.org/techniques/T1505/006","tactics":["persistence"],"platforms":["ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0535","stix_id":"x-mitre-detection-strategy--000d7b6f-0bb5-4144-a3eb-1aa822433da1","name":"Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access","url":"https://attack.mitre.org/detectionstrategies/DET0535","analytics":[{"id":"AN1475","stix_id":"x-mitre-analytic--9696a221-35b9-4576-ae75-714c902c2889","name":"Analytic 1475","description":"Malicious VIB installation for persistence via `esxcli software vib install` using `--force` or `--no-sig-check`, enabling custom startup scripts or firewall rules. Behavior chain: (1) unsigned/suspicious VIB installation → (2) startup script or binary placed in persistent boot path → (3) persistence across reboot via /etc/rc.local.d or other boot hook).","url":"https://attack.mitre.org/detectionstrategies/DET0535#AN1475","platforms":["ESXi"],"log_source_references":[{"name":"esxi:esxupdate","channel":"/var/log/esxupdate.log contains VIB installed with `--force` or `--no-sig-check` and non-standard acceptance levels","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"esxi-esxupdate"},{"name":"esxi:shell","channel":"`esxcli software vib install` with `--force` or `--no-sig-check` from shell history or `shell.log`","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"linux:fim","channel":"Changes to /etc/rc.local.d/local.sh or creation of unexpected startup files in persistent partitions (/etc/init.d, /store, /locker)","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"linux-fim"}],"mutable_elements":[{"field":"AcceptanceLevel","description":"Some environments may intentionally permit CommunitySupported or unsigned VIBs—filter by known allowed publishers."},{"field":"InstallCommandThreshold","description":"Set alerting thresholds for frequency of VIB install attempts per host/user/time window."},{"field":"StartupPathRegex","description":"Tune regex for monitoring startup file locations based on ESXi image customization."}],"live":true,"detection_strategies":["DET0535"],"techniques":["T1505.006"]}],"live":true,"version":"1.0","techniques":["T1505.006"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}