Techniques › T1210 › AN0329
AN0329 Analytic 0329
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects exploitation targeting ESXi/vCenter by correlating attempts to reach known exploitable endpoints (OpenSLP 427, CIM 5989, Hostd/Vpxa HTTPS 443, ESXi SOAP) with vmkernel/hostd crashes, unexpected hostd/vpxa restarts, or new reverse/outbound connections from ESXi host/vCenter to internal assets.</p>
- Detects
- T1210 Exploitation of Remote Services
- Part of
- DET0118 Exploitation of Remote Services – multi-platform lateral movement detection
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:hostd | Keywords: 'Backtrace','Signal 11','PANIC','hostd restarted','assert' or 'Service terminated unexpectedly' in /var/log/hostd.log, /var/log/vmkernel.log, /var/log/syslog.log. | DC0038 Application Log Content |
| NSM:Flow | Inbound to tcp/427 (OpenSLP), tcp/443 (vSphere APIs), tcp/902, tcp/5989 followed by new unexpected outbound sessions from the ESXi/vCenter host. | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ESXiServicePorts | 427, 443, 902, 5989; modify per version/hardening. |
MgmtCIDRs | Legit management networks for vCenter/ESXi. |
RestartKeywords | Crash/restart patterns to match in logs. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2021-41773 | Apache HTTP Server | Mapped |
| CVE-2021-42013 | Apache HTTP Server | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | Mapped |