kevmap

TechniquesT1210 › AN0329

AN0329 Analytic 0329

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects exploitation targeting ESXi/vCenter by correlating attempts to reach known exploitable endpoints (OpenSLP 427, CIM 5989, Hostd/Vpxa HTTPS 443, ESXi SOAP) with vmkernel/hostd crashes, unexpected hostd/vpxa restarts, or new reverse/outbound connections from ESXi host/vCenter to internal assets.</p>
Detects
T1210 Exploitation of Remote Services
Part of
DET0118 Exploitation of Remote Services – multi-platform lateral movement detection

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:hostdKeywords: 'Backtrace','Signal 11','PANIC','hostd restarted','assert' or 'Service terminated unexpectedly' in /var/log/hostd.log, /var/log/vmkernel.log, /var/log/syslog.log.DC0038 Application Log Content
NSM:FlowInbound to tcp/427 (OpenSLP), tcp/443 (vSphere APIs), tcp/902, tcp/5989 followed by new unexpected outbound sessions from the ESXi/vCenter host.DC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ESXiServicePorts427, 443, 902, 5989; modify per version/hardening.
MgmtCIDRsLegit management networks for vCenter/ESXi.
RestartKeywordsCrash/restart patterns to match in logs.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-41773Apache HTTP ServerMapped
CVE-2021-42013Apache HTTP ServerMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2024-54085AMI MegaRAC SPxMapped