kevmap

Log sources › esxi:esxupdate

esxi:esxupdate

Inverted view: what can be detected if this is the log you have. ESXi

2
channels
2
analytics
2
techniques
0
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/esxupdate.log contains VIB installed with `--force` or `--no-sig-check` and non-standard acceptance levels DC0038 Application Log Content AN1475 1
/var/log/esxupdate.log or /var/log/vmksummary.log DC0082 Network Connection Creation AN1023 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1090.003 Multi-hop Proxycommand and control30
T1505.006 vSphere Installation Bundlespersistence00