Techniques › T1005 › AN1074
AN1074 Analytic 1074
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Adversaries accessing datastore or configuration files via
vim-cmd, esxcli, or SCP to extract logs, VMs, or host configurations.</p>- Detects
- T1005 Data from Local System
- Part of
- DET0380 Detection of Local Data Collection Prior to Exfiltration
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxis:vmkernel | Datastore Access | DC0055 File Access |
| esxi:hostd | Command Execution | DC0064 Command Execution |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AccessPathRegex | Regex for filtering targeted VM paths or files like *.vmdk, *.vmx. |
InteractiveShellUsage | Tune to distinguish between interactive and script-driven data access. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2013-0629 | Adobe ColdFusion | Mapped |
| CVE-2017-11292 | Adobe Flash Player | Mapped |
| CVE-2017-5638 | Apache Struts | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |
| CVE-2020-5902 | F5 BIG-IP | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | Mapped |
| CVE-2021-27101 | Accellion FTA | Mapped |
| CVE-2021-27102 | Accellion FTA | Mapped |
| CVE-2021-27103 | Accellion FTA | Mapped |
| CVE-2021-27104 | Accellion FTA | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | Mapped |
| CVE-2023-36884 | Microsoft Windows | Stale |
| CVE-2023-38831 | RARLAB WinRAR | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2024-38475 | Apache HTTP Server | Mapped |
| CVE-2024-41713 | Mitel MiCollab | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | Mapped |
| CVE-2024-50302 | Linux Kernel | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-53150 | Linux Kernel | Mapped |
| CVE-2024-55550 | Mitel MiCollab | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | Mapped |
| CVE-2025-21418 | Microsoft Windows | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | Mapped |
| CVE-2025-24991 | Microsoft Windows | Mapped |
| CVE-2025-43200 | Apple Multiple Products | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | Mapped |