Log sources › esxi:vmkernel
esxi:vmkernel
Inverted view: what can be detected if this is the log you have. ESXi
43
channels
47
analytics
46
techniques
104
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/var/log/vmkernel.log |
DC0061 File Modification DC0064 Command Execution DC0078 Network Traffic Flow |
AN0116 AN0207 AN1023 AN1455 AN1629 | 5 |
DCUI shell start, BusyBox activity |
DC0064 Command Execution | AN1083 | 1 |
DNS lookups resolving to domains with rapid changes in registration metadata |
DC0101 Domain Registration | AN1152 | 1 |
Datastore modification events |
DC0059 File Metadata | AN1068 | 1 |
Disabling or modifying firewall rules |
DC0043 Firewall Disable | AN0890 | 0 |
Exec |
DC0032 Process Creation | AN0987 | 1 |
HTTPS POST connections to pastebin-like domains |
DC0085 Network Traffic Content | AN0790 | 1 |
HTTPS POST connections to webhook endpoints |
DC0085 Network Traffic Content | AN0439 | 1 |
HTTPS traffic to repository domains |
DC0078 Network Traffic Flow | AN0898 | 1 |
Inspection of sockets showing encrypted sessions from non-baseline processes |
DC0085 Network Traffic Content | AN0762 | 1 |
Network activity |
DC0085 Network Traffic Content | AN0033 | 1 |
None |
DC0078 Network Traffic Flow DC0082 Network Connection Creation |
AN0925 AN1232 AN1379 | 3 |
Outbound traffic using encoded payloads post-login |
DC0085 Network Traffic Content | AN0305 | 1 |
Startup script and task execution logs |
DC0001 Scheduled Job Creation | AN0262 | 1 |
Storage access and file ops |
DC0059 File Metadata | AN0654 | 1 |
Suspicious traffic filtered or redirected by VM networking stack |
DC0085 Network Traffic Content | AN1152 | 1 |
Unauthorized file modifications within datastore volumes via shell access or vCLI |
DC0061 File Modification | AN0665 | 1 |
Unexpected restarts of management agents or shell access |
DC0064 Command Execution | AN1510 | 1 |
Upload of file to datastore |
DC0059 File Metadata | AN0519 | 1 |
VM exit/entry anomalies, unexpected hypercalls, or kernel module loading |
DC0031 Kernel Module Load | AN0615 | 1 |
VMCI syslog entries |
DC0085 Network Traffic Content | AN1257 | 1 |
VMFS access logs |
DC0055 File Access | AN0044 | 1 |
VMFS file creation |
DC0039 File Creation | AN0197 | 1 |
VMX startup messages without associated vCenter inventory records |
DC0028 Image Metadata | AN0912 | 1 |
boot |
DC0029 Script Execution | AN0314 | 1 |
egress log analysis |
DC0078 Network Traffic Flow | AN1392 | 1 |
egress logs |
DC0078 Network Traffic Flow | AN1416 | 1 |
esxcli system account add |
DC0064 Command Execution | AN1238 | 1 |
esxcli, vim-cmd invocation |
DC0064 Command Execution | AN1537 | 1 |
file delete|datastore purge |
DC0098 Volume Deletion | AN0415 | 1 |
file write |
DC0039 File Creation | AN0168 | 1 |
module load |
DC0016 Module Load | AN0987 | 1 |
network activity |
DC0082 Network Connection Creation | AN1192 | 1 |
network flows to external cloud services |
DC0078 Network Traffic Flow | AN1574 | 1 |
network session initiation with external HTTPS services |
DC0082 Network Connection Creation | AN1515 | 1 |
network stack module logs |
DC0085 Network Traffic Content | AN0991 | 1 |
port 22 access |
DC0078 Network Traffic Flow | AN1640 | 1 |
protocol egress |
DC0082 Network Connection Creation | AN0371 | 1 |
rename .vmdk to .*.locked|datastore write spike |
DC0061 File Modification | AN0605 | 1 |
snapshot create/write events |
DC0057 Snapshot Creation | AN0727 | 1 |
spawned shell or execution environment activity |
DC0032 Process Creation | AN0807 | 1 |
unexpected module load |
DC0016 Module Load | AN0952 | 1 |
vim.fault.*, DCUI login, SSH shell |
DC0067 Logon Session Creation | AN0754 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | T1486 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1105 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1105 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1105 | Mapped |
| CVE-2010-2883 | Adobe Acrobat and Reader | T1027 | Mapped |
| CVE-2011-0611 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-0754 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-1535 | Adobe Flash Player | T1105 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 T1105 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1105 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1105 T1486 | Mapped |
| CVE-2016-0984 | Adobe Flash Player and AIR | T1105 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1105 T1486 | Mapped |
| CVE-2016-4117 | Adobe Flash Player | T1105 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1105 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 | Mapped |
| CVE-2018-15982 | Adobe Flash Player | T1105 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1041 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1485 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1041 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1486 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1082 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 T1486 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1090 T1485 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1090 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1486 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1105 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1485 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1027 T1082 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1027 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1486 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1027 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1486 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1105 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1486 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1136.001 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1486 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1027 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1505 | Mapped |
| CVE-2022-30190 | Microsoft Windows | T1105 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1567 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1136.001 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1486 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 | Mapped |
| CVE-2023-20867 | VMware Tools | T1105 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1105 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 T1105 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1105 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1486 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1021 T1486 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 T1105 | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | T1105 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1082 T1105 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1105 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1486 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1105 | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | T1105 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1041 T1053 T1059.004 T1105 T1486 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 T1059.004 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1082 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1105 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1105 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1567 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1082 T1105 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 T1059.004 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1041 T1053 T1570 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1105 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1041 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1485 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1611 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1611 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1611 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1485 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 T1485 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1105 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1105 | Stale |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1041 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1105 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1505 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 T1567 | Mapped |