kevmap

TechniquesT1005 › AN1074

AN1074 Analytic 1074

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversaries accessing datastore or configuration files via vim-cmd, esxcli, or SCP to extract logs, VMs, or host configurations.</p>
Detects
T1005 Data from Local System
Part of
DET0380 Detection of Local Data Collection Prior to Exfiltration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxis:vmkernelDatastore AccessDC0055 File Access
esxi:hostdCommand ExecutionDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AccessPathRegexRegex for filtering targeted VM paths or files like *.vmdk, *.vmx.
InteractiveShellUsageTune to distinguish between interactive and script-driven data access.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2013-0629Adobe ColdFusionMapped
CVE-2017-11292Adobe Flash PlayerMapped
CVE-2017-5638Apache StrutsMapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA)Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2019-1653Cisco Small Business RV320 and RV325 RoutersMapped
CVE-2019-5591Fortinet FortiOSMapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2021-26085Atlassian Confluence ServerMapped
CVE-2021-26855Microsoft Exchange ServerMapped
CVE-2021-27101Accellion FTAMapped
CVE-2021-27102Accellion FTAMapped
CVE-2021-27103Accellion FTAMapped
CVE-2021-27104Accellion FTAMapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU)Mapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped
CVE-2023-38950ZKTeco BioTimeMapped
CVE-2023-49103ownCloud ownCloud graphapiMapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2024-0769D-Link DIR-859 RouterMapped
CVE-2024-23692Rejetto HTTP File ServerMapped
CVE-2024-24919Check Point Quantum Security GatewaysMapped
CVE-2024-34102Adobe Commerce and Magento Open SourceMapped
CVE-2024-38475Apache HTTP ServerMapped
CVE-2024-41713Mitel MiCollabMapped
CVE-2024-48248NAKIVO Backup and ReplicationMapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-4978Justice AV Solutions Viewer Mapped
CVE-2024-50302Linux KernelMapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-53150Linux KernelMapped
CVE-2024-55550Mitel MiCollabMapped
CVE-2025-0111Palo Alto Networks PAN-OSMapped
CVE-2025-21418Microsoft WindowsMapped
CVE-2025-22226VMware ESXi, Workstation, and FusionMapped
CVE-2025-24991Microsoft WindowsMapped
CVE-2025-43200Apple Multiple ProductsMapped
CVE-2025-48927TeleMessage TM SGNLMapped
CVE-2025-48928TeleMessage TM SGNLMapped