Techniques › T1611 › AN0615
AN0615 Analytic 0615
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detection of ESXi escape attempts by monitoring for anomalies in hypervisor logs such as unexpected VM operations, privilege escalation events, or attempts to load malicious kernel modules within the hypervisor environment.</p>
- Detects
- T1611 Escape to Host
- Part of
- DET0219 Detection Strategy for Escape to Host
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:vmkernel | VM exit/entry anomalies, unexpected hypercalls, or kernel module loading | DC0031 Kernel Module Load |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AllowedKernelModules | Modules permitted in the hypervisor. Loading any module outside of this list may indicate compromise. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2025-22224 | VMware ESXi and Workstation | Mapped |
| CVE-2025-22225 | VMware ESXi | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | Mapped |