kevmap

Log sources › esxi:vpxa

esxi:vpxa

Inverted view: what can be detected if this is the log you have. ESXi

3
channels
3
analytics
3
techniques
15
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
connection attempts and data transmission logs DC0078 Network Traffic Flow AN0991 1
user login from unexpected IP or non-admin user role DC0002 User Account Authentication AN0337 1
vim.SessionManager.login / vim.AccountManager.createUser DC0066 Active Directory Object Modification AN0269 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1041 Exfiltration Over C2 Channelexfiltration512
T1098 Account Manipulationpersistence, privilege escalation342
T1531 Account Access Removalimpact91

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2012-0767Adobe Flash Player T1098 Mapped
CVE-2018-4878Adobe Flash Player T1041 Mapped
CVE-2019-0604Microsoft SharePoint T1041 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 Mapped
CVE-2021-32030ASUS Routers T1098 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 Mapped
CVE-2023-34362Progress MOVEit Transfer T1531 Mapped
CVE-2023-38831RARLAB WinRAR T1041 Mapped
CVE-2023-5631Roundcube Webmail T1041 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 Mapped
CVE-2024-4577PHP Group PHP T1041 Mapped
CVE-2024-55550Mitel MiCollab T1041 Mapped
CVE-2025-32756Fortinet Multiple Products T1041 Mapped
CVE-2025-33053Microsoft Windows T1041 Mapped