Log sources › esxis:vmkernel
esxis:vmkernel
Inverted view: what can be detected if this is the log you have. ESXi
1
channels
1
analytics
1
techniques
46
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Datastore Access |
DC0055 File Access | AN1074 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1005 Data from Local System | collection | 14 | 46 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2013-0629 | Adobe ColdFusion | T1005 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1005 | Mapped |
| CVE-2017-5638 | Apache Struts | T1005 | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | T1005 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1005 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1005 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1005 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1005 | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1005 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1005 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1005 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1005 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1005 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1005 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1005 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1005 | Stale |
| CVE-2023-38831 | RARLAB WinRAR | T1005 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1005 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1005 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1005 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1005 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1005 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1005 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1005 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1005 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1005 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1005 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1005 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1005 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1005 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1005 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1005 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1005 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1005 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1005 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1005 | Mapped |