kevmap

Log sources › esxi:hostd

esxi:hostd

Inverted view: what can be detected if this is the log you have. ESXi, IaaS

51
channels
54
analytics
53
techniques
221
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/hostd.log DC0064 Command Execution
DC0088 Logon Session Metadata
AN0175 AN0593 2
/var/log/hostd.log API calls reading/altering time/ntp settings DC0034 Process Metadata AN0433 1
/var/log/hostd.log anomalies (faults, crashes, restarts) around inbound connections DC0038 Application Log Content AN0224 1
CLI network calls DC0078 Network Traffic Flow AN0640 AN1602 2
Command Execution DC0064 Command Execution AN1074 1
Execution of '/bin/vmx' or modifications to '/etc/rc.local.d/local.sh' DC0064 Command Execution AN0912 1
Guest Operations API invocation: StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, InitiateFileTransferFromGuest DC0038 Application Log Content AN0646 1
Host daemon command log entries related to vib enumeration DC0038 Application Log Content AN1104 1
Keywords: 'Backtrace','Signal 11','PANIC','hostd restarted','assert' or 'Service terminated unexpectedly' in /var/log/hostd.log, /var/log/vmkernel.log, /var/log/syslog.log. DC0038 Application Log Content AN0329 1
Log entries indicating VM powered off or forcibly terminated DC0033 Process Termination AN0064 1
New extension/module install with unknown vendor ID DC0038 Application Log Content AN1510 1
None DC0064 Command Execution AN0562 AN1586 2
Powering off or restarting host DC0018 Host Status AN1541 1
Remote access API calls and file uploads DC0021 OS API Execution AN1068 1
Service events DC0041 Service Metadata AN0987 1
Service initiated connections DC0082 Network Connection Creation AN0654 1
Service-Based Network Connection DC0082 Network Connection Creation AN1297 1
Stop VM or disable service events via vim-cmd DC0041 Service Metadata AN0064 1
System service interactions DC0082 Network Connection Creation AN0033 1
binary or module replacement event DC0061 File Modification AN0952 1
boot DC0061 File Modification AN0314 1
command execution DC0064 Command Execution AN0168 1
command log DC0064 Command Execution AN0906 1
datastore file access DC0055 File Access AN0439 AN0898 AN1574 3
datastore/log file access DC0055 File Access AN0790 1
esxcli network firewall set commands DC0064 Command Execution AN0409 1
esxcli system syslog config set or reload DC0064 Command Execution AN0670 0
event stream DC0064 Command Execution AN0426 AN1416 2
execution + payload hints DC0064 Command Execution AN1392 1
execution of esxcli with args matching 'storage', 'filesystem', 'core device list' DC0032 Process Creation AN0539 1
file copy or datastore upload via HTTPS DC0055 File Access AN1515 1
host daemon events related to VM operations and configuration queries during reconnaissance DC0032 Process Creation AN1554 1
host daemon events related to file or VM permission changes DC0059 File Metadata AN0837 1
logline inspection DC0064 Command Execution AN0371 1
method=RemoveUser or esxcli system account remove invocation DC0009 User Account Deletion AN0337 1
modification of config files or shell command execution DC0064 Command Execution AN0232 1
modification of crontab or local.sh entries DC0061 File Modification AN0807 1
process DC0032 Process Creation AN1018 1
process execution across cloud VM DC0032 Process Creation AN0198 1
read: Access to sensitive log files by non-admin users DC0055 File Access AN0709 1
registers services with legitimate-sounding names DC0041 Service Metadata AN0359 1
rm, clearlogs, logrotate DC0040 File Deletion AN0524 1
scp/ssh used to move file across hosts DC0064 Command Execution AN0519 1
service state change DC0065 Service Modification AN2044 1
shell access or job registration DC0064 Command Execution AN0262 1
snapshot.removeall or snapshot file deletion DC0049 Snapshot Deletion AN0935 1
task creation events DC0001 Scheduled Job Creation AN0987 1
unexpected script invocations producing long encoded strings DC0038 Application Log Content AN0930 1
unexpected script/command invocations via hostd DC0038 Application Log Content AN0348 1
vSphere API calls modifying firewall settings DC0051 Firewall Rule Modification AN0409 1
vSphere File API Access DC0055 File Access AN1043 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1001.003 Protocol or Service Impersonationcommand and control20
T1005 Data from Local Systemcollection1446
T1016 System Network Configuration Discoverydiscovery121
T1016.001 Internet Connection Discoverydiscovery00
T1018 Remote System Discoverydiscovery172
T1027 Obfuscated Files or Informationstealth945
T1036 Masqueradingstealth402
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1049 System Network Connections Discoverydiscovery91
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.003 Cronexecution, persistence, privilege escalation60
T1059.006 Pythonexecution130
T1070 Indicator Removalstealth203
T1074.002 Remote Data Stagingcollection00
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1083 File and Directory Discoverydiscovery245
T1102.003 One-Way Communicationcommand and control20
T1104 Multi-Stage Channelscommand and control00
T1105 Ingress Tool Transfercommand and control8735
T1124 System Time Discoverydiscovery30
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1190 Exploit Public-Facing Applicationinitial access149157
T1210 Exploitation of Remote Serviceslateral movement154
T1222 File and Directory Permissions Modificationdefense impairment21
T1480 Execution Guardrailsstealth00
T1489 Service Stopimpact201
T1490 Inhibit System Recoveryimpact272
T1491.001 Internal Defacementimpact40
T1505 Server Software Componentpersistence12
T1518 Software Discoverydiscovery40
T1529 System Shutdown/Rebootimpact80
T1531 Account Access Removalimpact91
T1554 Compromise Host Software Binarypersistence60
T1564.006 Run Virtual Instancestealth20
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1570 Lateral Tool Transferlateral movement61
T1654 Log Enumerationdiscovery00
T1675 ESXi Administration Commandexecution00
T1680 Local Storage Discoverydiscovery00
T1685 Disable or Modify Toolsdefense impairment1640
T1686 Disable or Modify System Firewalldefense impairment70

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-3960Adobe BlazeDS T1190 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 Mapped
CVE-2010-1297Adobe Flash Player T1105 Mapped
CVE-2010-2861Adobe ColdFusion T1105 T1190 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 Mapped
CVE-2011-0611Adobe Flash Player T1105 Mapped
CVE-2012-0754Adobe Flash Player T1105 Mapped
CVE-2012-1535Adobe Flash Player T1105 Mapped
CVE-2013-0625Adobe ColdFusion T1190 Mapped
CVE-2013-0629Adobe ColdFusion T1005 T1190 Mapped
CVE-2013-0631Adobe ColdFusion T1190 Mapped
CVE-2013-0632Adobe ColdFusion T1190 Mapped
CVE-2013-0641Adobe Reader T1048 T1105 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1190 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1190 Mapped
CVE-2015-5119Adobe Flash Player T1105 Mapped
CVE-2015-8651Adobe Flash Player T1105 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 Mapped
CVE-2016-10033PHP PHPMailer T1190 Mapped
CVE-2016-1019Adobe Flash Player T1105 Mapped
CVE-2016-4117Adobe Flash Player T1105 Mapped
CVE-2016-4437Apache Shiro T1190 Mapped
CVE-2017-11292Adobe Flash Player T1005 T1105 Mapped
CVE-2017-12637SAP NetWeaver T1083 T1190 Mapped
CVE-2017-5638Apache Struts T1005 T1190 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 Mapped
CVE-2017-9805Apache Struts T1190 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1190 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 Mapped
CVE-2018-11776Apache Struts T1190 Mapped
CVE-2018-13379Fortinet FortiOS T1190 Mapped
CVE-2018-15961Adobe ColdFusion T1190 Mapped
CVE-2018-15982Adobe Flash Player T1105 Mapped
CVE-2018-4939Adobe ColdFusion T1190 Mapped
CVE-2018-6789Exim Exim T1190 Mapped
CVE-2018-7600Drupal Drupal Core T1190 Mapped
CVE-2019-0604Microsoft SharePoint T1190 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1083 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1005 T1190 Mapped
CVE-2019-13608Citrix StoreFront Server T1005 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 T1190 Mapped
CVE-2019-17558Apache Solr T1190 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1190 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1083 Mapped
CVE-2019-5591Fortinet FortiOS T1005 Mapped
CVE-2020-0688Microsoft Exchange Server T1190 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1190 Mapped
CVE-2020-17530Apache Struts T1190 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1190 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 Mapped
CVE-2020-5902F5 BIG-IP T1005 T1190 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 Mapped
CVE-2021-21972VMware vCenter Server T1190 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1190 Mapped
CVE-2021-21975VMware vRealize Operations Manager API T1190 Mapped
CVE-2021-22005VMware vCenter Server T1190 Mapped
CVE-2021-22017VMware vCenter Server T1190 Mapped
CVE-2021-22204Perl Exiftool T1190 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1190 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1190 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1190 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 T1190 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 Mapped
CVE-2021-26858Microsoft Exchange Server T1190 Mapped
CVE-2021-27065Microsoft Exchange Server T1190 Mapped
CVE-2021-27101Accellion FTA T1005 Mapped
CVE-2021-27102Accellion FTA T1005 T1190 Mapped
CVE-2021-27103Accellion FTA T1005 T1190 Mapped
CVE-2021-27104Accellion FTA T1005 T1190 Mapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software T1190 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1190 Mapped
CVE-2021-3129Laravel Ignition T1190 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 T1190 Mapped
CVE-2021-34523Microsoft Exchange Server T1190 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1105 T1190 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1190 Mapped
CVE-2021-36380Sunhillo SureLine T1190 Mapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP) T1190 Mapped
CVE-2021-39144XStream XStream T1190 Mapped
CVE-2021-39226Grafana Labs Grafana T1190 Mapped
CVE-2021-40449Microsoft Windows T1016 T1027 Mapped
CVE-2021-40539Zoho ManageEngine T1027 T1190 Mapped
CVE-2021-40655D-Link DIR-605 Router T1190 Mapped
CVE-2021-41773Apache HTTP Server T1210 Mapped
CVE-2021-42013Apache HTTP Server T1210 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1027 T1190 Mapped
CVE-2021-44228Apache Log4j2 T1190 Mapped
CVE-2021-44515Zoho Desktop Central T1105 T1190 Mapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1190 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 T1190 Mapped
CVE-2022-0028Palo Alto Networks PAN-OS T1190 Mapped
CVE-2022-1040Sophos Firewall T1190 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1190 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1190 Mapped
CVE-2022-20821Cisco IOS XR T1190 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1190 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1190 Mapped
CVE-2022-22965VMware Spring Framework T1190 Mapped
CVE-2022-23131Zabbix Frontend T1190 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 T1190 Mapped
CVE-2022-26134Atlassian Confluence Server/Data Center T1190 Mapped
CVE-2022-26258D-Link DIR-820L T1190 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 T1048 T1190 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 T1048 T1190 Mapped
CVE-2022-28810Zoho ManageEngine T1190 Mapped
CVE-2022-29303SolarView Compact T1505 Mapped
CVE-2022-29464WSO2 Multiple Products T1190 Mapped
CVE-2022-30190Microsoft Windows T1105 Mapped
CVE-2022-35914Teclib GLPI T1190 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1190 Mapped
CVE-2022-39197Fortra Cobalt Strike T1190 Mapped
CVE-2022-40684Fortinet Multiple Products T1190 Mapped
CVE-2022-41082Microsoft Exchange Server T1567 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2022-41328Fortinet FortiOS T1037 T1049 Mapped
CVE-2022-42475Fortinet FortiOS T1190 Mapped
CVE-2022-42948Fortra Cobalt Strike T1190 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1190 Mapped
CVE-2022-47966Zoho ManageEngine T1190 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1190 T1210 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1190 Mapped
CVE-2023-20867VMware Tools T1105 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1190 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1190 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1105 T1190 Mapped
CVE-2023-22952SugarCRM Multiple Products T1083 T1190 Stale
CVE-2023-26359Adobe ColdFusion T1190 Mapped
CVE-2023-26360Adobe ColdFusion T1036.005 T1105 T1190 Mapped
CVE-2023-27350PaperCut MF/NG T1105 T1190 Mapped
CVE-2023-27524Apache Superset T1190 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1190 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1105 Mapped
CVE-2023-29298Adobe ColdFusion T1190 Mapped
CVE-2023-29300Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-29492Novi Survey Novi Survey T1190 Mapped
CVE-2023-33246Apache RocketMQ T1190 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 T1105 T1190 T1531 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1105 T1190 Mapped
CVE-2023-36844Juniper Junos OS T1190 Mapped
CVE-2023-36845Juniper Junos OS T1190 Mapped
CVE-2023-36846Juniper Junos OS T1190 Mapped
CVE-2023-36847Juniper Junos OS T1190 Mapped
CVE-2023-36851Juniper Junos OS T1190 Mapped
CVE-2023-36884Microsoft Windows T1005 T1489 T1490 Stale
CVE-2023-38035Ivanti Sentry T1018 T1105 T1190 Mapped
CVE-2023-38203Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-38205Adobe ColdFusion T1190 Mapped
CVE-2023-38831RARLAB WinRAR T1005 T1053 T1105 Mapped
CVE-2023-38950ZKTeco BioTime T1005 T1190 Mapped
CVE-2023-42793JetBrains TeamCity T1190 Mapped
CVE-2023-44487IETF HTTP/2 T1190 Mapped
CVE-2023-46604Apache ActiveMQ T1190 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1190 Mapped
CVE-2023-48365Qlik Sense T1190 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1105 T1190 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 T1190 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1105 T1190 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 T1190 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1190 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1190 Mapped
CVE-2024-21762Fortinet FortiOS T1190 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1190 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1190 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 T1105 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1005 Mapped
CVE-2024-27198JetBrains TeamCity T1190 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 T1190 Mapped
CVE-2024-38475Apache HTTP Server T1005 T1190 Mapped
CVE-2024-41713Mitel MiCollab T1005 Mapped
CVE-2024-4358Progress Telerik Report Server T1190 Mapped
CVE-2024-4577PHP Group PHP T1053 T1190 T1570 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1005 T1190 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1190 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 T1105 Mapped
CVE-2024-50302Linux Kernel T1005 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 Mapped
CVE-2024-53150Linux Kernel T1005 Mapped
CVE-2024-53704SonicWall SonicOS T1083 Mapped
CVE-2024-54085AMI MegaRAC SPx T1210 Mapped
CVE-2024-55550Mitel MiCollab T1005 T1190 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1190 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1190 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1018 T1190 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1190 Mapped
CVE-2025-21391Microsoft Windows T1490 Mapped
CVE-2025-21418Microsoft Windows T1005 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1190 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1190 Mapped
CVE-2025-24991Microsoft Windows T1005 Mapped
CVE-2025-25257Fortinet FortiWeb T1190 Mapped
CVE-2025-31200Apple Multiple Products T1105 Stale
CVE-2025-31201Apple Multiple Products T1105 Stale
CVE-2025-34028Commvault Command Center T1190 Mapped
CVE-2025-35939Craft CMS Craft CMS T1190 Mapped
CVE-2025-42599Qualitia Active! Mail T1190 Mapped
CVE-2025-42999SAP NetWeaver T1190 Mapped
CVE-2025-43200Apple Multiple Products T1005 T1105 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 Mapped
CVE-2025-49704Microsoft SharePoint T1190 Mapped
CVE-2025-49706Microsoft SharePoint T1190 T1505 Mapped
CVE-2025-53770Microsoft SharePoint T1190 Mapped
CVE-2025-54309CrushFTP CrushFTP T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1190 Mapped