kevmap

Log sources › esxi:vmkernel

esxi:vmkernel

Inverted view: what can be detected if this is the log you have. ESXi

43
channels
47
analytics
46
techniques
104
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/vmkernel.log DC0061 File Modification
DC0064 Command Execution
DC0078 Network Traffic Flow
AN0116 AN0207 AN1023 AN1455 AN1629 5
DCUI shell start, BusyBox activity DC0064 Command Execution AN1083 1
DNS lookups resolving to domains with rapid changes in registration metadata DC0101 Domain Registration AN1152 1
Datastore modification events DC0059 File Metadata AN1068 1
Disabling or modifying firewall rules DC0043 Firewall Disable AN0890 0
Exec DC0032 Process Creation AN0987 1
HTTPS POST connections to pastebin-like domains DC0085 Network Traffic Content AN0790 1
HTTPS POST connections to webhook endpoints DC0085 Network Traffic Content AN0439 1
HTTPS traffic to repository domains DC0078 Network Traffic Flow AN0898 1
Inspection of sockets showing encrypted sessions from non-baseline processes DC0085 Network Traffic Content AN0762 1
Network activity DC0085 Network Traffic Content AN0033 1
None DC0078 Network Traffic Flow
DC0082 Network Connection Creation
AN0925 AN1232 AN1379 3
Outbound traffic using encoded payloads post-login DC0085 Network Traffic Content AN0305 1
Startup script and task execution logs DC0001 Scheduled Job Creation AN0262 1
Storage access and file ops DC0059 File Metadata AN0654 1
Suspicious traffic filtered or redirected by VM networking stack DC0085 Network Traffic Content AN1152 1
Unauthorized file modifications within datastore volumes via shell access or vCLI DC0061 File Modification AN0665 1
Unexpected restarts of management agents or shell access DC0064 Command Execution AN1510 1
Upload of file to datastore DC0059 File Metadata AN0519 1
VM exit/entry anomalies, unexpected hypercalls, or kernel module loading DC0031 Kernel Module Load AN0615 1
VMCI syslog entries DC0085 Network Traffic Content AN1257 1
VMFS access logs DC0055 File Access AN0044 1
VMFS file creation DC0039 File Creation AN0197 1
VMX startup messages without associated vCenter inventory records DC0028 Image Metadata AN0912 1
boot DC0029 Script Execution AN0314 1
egress log analysis DC0078 Network Traffic Flow AN1392 1
egress logs DC0078 Network Traffic Flow AN1416 1
esxcli system account add DC0064 Command Execution AN1238 1
esxcli, vim-cmd invocation DC0064 Command Execution AN1537 1
file delete|datastore purge DC0098 Volume Deletion AN0415 1
file write DC0039 File Creation AN0168 1
module load DC0016 Module Load AN0987 1
network activity DC0082 Network Connection Creation AN1192 1
network flows to external cloud services DC0078 Network Traffic Flow AN1574 1
network session initiation with external HTTPS services DC0082 Network Connection Creation AN1515 1
network stack module logs DC0085 Network Traffic Content AN0991 1
port 22 access DC0078 Network Traffic Flow AN1640 1
protocol egress DC0082 Network Connection Creation AN0371 1
rename .vmdk to .*.locked|datastore write spike DC0061 File Modification AN0605 1
snapshot create/write events DC0057 Snapshot Creation AN0727 1
spawned shell or execution environment activity DC0032 Process Creation AN0807 1
unexpected module load DC0016 Module Load AN0952 1
vim.fault.*, DCUI login, SSH shell DC0067 Logon Session Creation AN0754 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1008 Fallback Channelscommand and control40
T1021 Remote Serviceslateral movement114
T1021.004 SSHlateral movement52
T1027 Obfuscated Files or Informationstealth945
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1041 Exfiltration Over C2 Channelexfiltration512
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.003 Cronexecution, persistence, privilege escalation60
T1059.004 Unix Shellexecution1814
T1059.012 Hypervisor CLIexecution90
T1070.006 Timestompstealth60
T1070.009 Clear Persistencestealth00
T1074 Data Stagedcollection20
T1074.001 Local Data Stagingcollection40
T1074.002 Remote Data Stagingcollection00
T1082 System Information Discoverydiscovery337
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1095 Non-Application Layer Protocolcommand and control30
T1102 Web Servicecommand and control130
T1105 Ingress Tool Transfercommand and control8735
T1132 Data Encodingcommand and control00
T1136.001 Local Accountpersistence182
T1485 Data Destructionimpact206
T1486 Data Encrypted for Impactimpact1615
T1491 Defacementimpact00
T1505 Server Software Componentpersistence12
T1554 Compromise Host Software Binarypersistence60
T1564.006 Run Virtual Instancestealth20
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1570 Lateral Tool Transferlateral movement61
T1573 Encrypted Channelcommand and control60
T1611 Escape to Hostprivilege escalation23
T1665 Hide Infrastructurecommand and control00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-3960Adobe BlazeDS T1486 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 Mapped
CVE-2010-1297Adobe Flash Player T1105 Mapped
CVE-2010-2861Adobe ColdFusion T1105 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 Mapped
CVE-2011-0611Adobe Flash Player T1105 Mapped
CVE-2012-0754Adobe Flash Player T1105 Mapped
CVE-2012-1535Adobe Flash Player T1105 Mapped
CVE-2013-0641Adobe Reader T1048 T1105 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2015-5119Adobe Flash Player T1105 Mapped
CVE-2015-8651Adobe Flash Player T1105 T1486 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2016-1019Adobe Flash Player T1105 T1486 Mapped
CVE-2016-4117Adobe Flash Player T1105 Mapped
CVE-2017-11292Adobe Flash Player T1105 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 Mapped
CVE-2018-15982Adobe Flash Player T1105 Mapped
CVE-2018-4878Adobe Flash Player T1041 Mapped
CVE-2018-7600Drupal Drupal Core T1485 Mapped
CVE-2019-0604Microsoft SharePoint T1041 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1486 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1082 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1486 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1090 T1485 Mapped
CVE-2021-26855Microsoft Exchange Server T1090 Mapped
CVE-2021-34473Microsoft Exchange Server T1486 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1105 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-39226Grafana Labs Grafana T1485 Mapped
CVE-2021-40449Microsoft Windows T1027 T1082 Mapped
CVE-2021-40539Zoho ManageEngine T1027 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1486 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1027 Mapped
CVE-2021-44228Apache Log4j2 T1486 Mapped
CVE-2021-44515Zoho Desktop Central T1105 Mapped
CVE-2021-45046Apache Log4j2 T1486 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-21999Microsoft Windows T1136.001 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1486 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 Mapped
CVE-2022-26500Veeam Backup & Replication T1048 Mapped
CVE-2022-26501Veeam Backup & Replication T1048 Mapped
CVE-2022-29303SolarView Compact T1505 Mapped
CVE-2022-30190Microsoft Windows T1105 Mapped
CVE-2022-41082Microsoft Exchange Server T1567 Mapped
CVE-2022-41328Fortinet FortiOS T1037 Mapped
CVE-2022-47966Zoho ManageEngine T1136.001 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1486 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 Mapped
CVE-2023-20867VMware Tools T1105 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1105 Mapped
CVE-2023-26360Adobe ColdFusion T1036.005 T1105 Mapped
CVE-2023-27350PaperCut MF/NG T1105 Mapped
CVE-2023-27532Veeam Backup & Replication T1486 Mapped
CVE-2023-28252Microsoft Windows T1021 T1486 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 T1105 Mapped
CVE-2023-29300Adobe ColdFusion T1105 Mapped
CVE-2023-34362Progress MOVEit Transfer T1082 T1105 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1105 Mapped
CVE-2023-36884Microsoft Windows T1486 Stale
CVE-2023-38035Ivanti Sentry T1105 Mapped
CVE-2023-38203Adobe ColdFusion T1105 Mapped
CVE-2023-38831RARLAB WinRAR T1041 T1053 T1059.004 T1105 T1486 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 Mapped
CVE-2023-43770Roundcube Webmail T1082 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1105 Mapped
CVE-2023-5631Roundcube Webmail T1041 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1105 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-23692Rejetto HTTP File Server T1082 T1105 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1059.004 Mapped
CVE-2024-4577PHP Group PHP T1041 T1053 T1570 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1105 Mapped
CVE-2024-55550Mitel MiCollab T1041 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 Mapped
CVE-2025-21391Microsoft Windows T1485 Mapped
CVE-2025-22224VMware ESXi and Workstation T1611 Mapped
CVE-2025-22225VMware ESXi T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1611 Mapped
CVE-2025-25181Advantive VeraCore T1485 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 T1485 Mapped
CVE-2025-31200Apple Multiple Products T1105 Stale
CVE-2025-31201Apple Multiple Products T1105 Stale
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-32756Fortinet Multiple Products T1041 Mapped
CVE-2025-33053Microsoft Windows T1041 Mapped
CVE-2025-43200Apple Multiple Products T1105 Mapped
CVE-2025-49706Microsoft SharePoint T1505 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 T1567 Mapped