kevmap

Log sources › esxi:vpxd

esxi:vpxd

Inverted view: what can be detected if this is the log you have. ESXi

9
channels
9
analytics
9
techniques
11
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/vmware/vpxd.log DC0002 User Account Authentication AN0593 1
ESXi process initiating asymmetric handshake with external host DC0038 Application Log Content AN1499 1
ESXi processes relaying traffic via SSH or unexpected ports DC0078 Network Traffic Flow AN1486 1
ESXi service connections on unexpected ports DC0078 Network Traffic Flow AN0636 1
None DC0078 Network Traffic Flow AN1379 1
Symmetric crypto routines triggered for external session DC0038 Application Log Content AN0403 1
TLS session established by ESXi service to unapproved endpoint DC0078 Network Traffic Flow AN0762 1
permission change operations on datastores or VMs DC0066 Active Directory Object Modification AN0837 1
vCenter Management DC0064 Command Execution AN1617 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1008 Fallback Channelscommand and control40
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1087 Account Discoverydiscovery166
T1222 File and Directory Permissions Modificationdefense impairment21
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-40449Microsoft Windows T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1573.001 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1573.001 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 Mapped
CVE-2023-38035Ivanti Sentry T1571 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped