Log sources › esxi:syslog
esxi:syslog
Inverted view: what can be detected if this is the log you have. ESXi
9
channels
9
analytics
9
techniques
12
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/var/log/syslog.log |
DC0078 Network Traffic Flow | AN1125 | 1 |
/var/log/vpxa.log task invocations tied to time configuration |
DC0005 Scheduled Job Metadata | AN0433 | 1 |
DNS resolution events leading to outbound traffic on unexpected ports |
DC0078 Network Traffic Flow | AN0731 | 1 |
Datastore file hidden or renamed unexpectedly |
DC0059 File Metadata | AN1387 | 1 |
Frequent DNS queries with high entropy names or NXDOMAIN results |
DC0078 Network Traffic Flow | AN1181 | 1 |
Frequent DNS resolution of same domain with rotating IPs |
DC0078 Network Traffic Flow | AN1334 | 1 |
boot logs |
DC0064 Command Execution | AN0660 | 1 |
esxcli network vswitch or DNS resolver configuration updates |
DC0078 Network Traffic Flow | AN0112 | 1 |
guest OS outbound transfer logs |
DC0055 File Access | AN0991 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1037.004 RC Scripts | persistence, privilege escalation | 0 | 0 |
| T1041 Exfiltration Over C2 Channel | exfiltration | 5 | 12 |
| T1071.004 DNS | command and control | 17 | 0 |
| T1124 System Time Discovery | discovery | 3 | 0 |
| T1564 Hide Artifacts | stealth | 10 | 0 |
| T1568 Dynamic Resolution | command and control | 2 | 0 |
| T1568.001 Fast Flux DNS | command and control | 0 | 0 |
| T1568.002 Domain Generation Algorithms | command and control | 2 | 0 |
| T1568.003 DNS Calculation | command and control | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2018-4878 | Adobe Flash Player | T1041 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1041 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1041 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1041 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1041 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1041 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 | Mapped |