Log sources › esxi:shell
esxi:shell
Inverted view: what can be detected if this is the log you have. ESXi
32
channels
37
analytics
36
techniques
47
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/root/.ash_history |
DC0064 Command Execution | AN1172 | 1 |
/root/.ash_history or /etc/init.d/* |
DC0032 Process Creation | AN0078 | 1 |
/var/log/shell.log |
DC0032 Process Creation DC0040 File Deletion |
AN0207 AN0395 AN0470 | 3 |
/var/log/shell.log entries containing "esxcli system clock get" |
DC0064 Command Execution | AN0433 | 1 |
/var/log/vmkernel.log, /var/log/vmkwarning.log |
DC0032 Process Creation | AN0567 | 1 |
CLI usage logs |
DC0064 Command Execution | AN0727 | 1 |
Command execution trace |
DC0064 Command Execution | AN0754 | 1 |
Execution of cat, tail, grep targeting /var/log/vmkernel.log or /var/log/hostd.log |
DC0064 Command Execution | AN0709 | 1 |
None |
DC0029 Script Execution DC0032 Process Creation DC0064 Command Execution |
AN0925 AN1018 AN1232 AN1640 | 4 |
Shell Access/Command Execution |
DC0064 Command Execution | AN1043 | 1 |
Shell Execution |
DC0032 Process Creation | AN0849 | 1 |
`esxcli software vib install` with `--force` or `--no-sig-check` from shell history or `shell.log` |
DC0064 Command Execution | AN1475 | 1 |
admin command usage |
DC0061 File Modification | AN0660 | 1 |
base64 or gzip use within shell session |
DC0064 Command Execution | AN0305 | 1 |
command IN ("esxcli vm process list", "vim-cmd vmsvc/getallvms") |
DC0064 Command Execution | AN0572 | 1 |
commands containing base64, openssl enc -base64, xxd -p |
DC0032 Process Creation | AN0348 | 1 |
commands containing long non-standard tokens or custom lookup tables |
DC0032 Process Creation | AN0930 | 1 |
esxcli software vib list |
DC0064 Command Execution | AN1104 | 1 |
esxcli system shutdown or reboot invoked |
DC0064 Command Execution | AN1541 | 1 |
esxcli system syslog config set --loghost='' or stopping hostd service |
DC0064 Command Execution | AN0890 | 0 |
esxcli system syslog config set/reload, services.sh restart/stop |
DC0064 Command Execution | AN2044 | 1 |
file write or edit |
DC0061 File Modification | AN0353 | 1 |
interactive shell |
DC0064 Command Execution | AN0098 | 1 |
invoked remote scripts (esxcli) |
DC0064 Command Execution | AN0197 | 1 |
mv, rename, or chmod commands moving VM files into hidden directories |
DC0064 Command Execution | AN1387 | 1 |
openssl|tar|dd |
DC0064 Command Execution | AN0605 | 1 |
scripts or binaries with misleading names |
DC0064 Command Execution | AN0359 | 1 |
shell command execution for chmod, chown, or file permission modification on VMFS or system files |
DC0064 Command Execution | AN0837 | 1 |
shell command execution for system discovery (vim-cmd, esxcli, vmware-cmd) targeting VM inventory and host configuration |
DC0064 Command Execution | AN1554 | 1 |
shell history |
DC0040 File Deletion | AN0116 | 1 |
snapshot create/copy, esxcli |
DC0064 Command Execution | AN0044 | 1 |
unset HISTFILE or HISTFILESIZE modifications |
DC0064 Command Execution | AN1558 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | T1486 | Mapped |
| CVE-2009-4324 | Adobe Acrobat and Reader | T1071.001 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1071.001 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1071.001 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1486 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1486 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1083 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1486 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1083 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 T1486 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1070.004 | Stale |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1090 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1090 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1486 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1071.001 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1071.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1070.004 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1486 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1070.004 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1486 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1486 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1486 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | T1098.004 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1071.001 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1486 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1070.004 T1083 | Stale |
| CVE-2023-26360 | Adobe ColdFusion | T1071.001 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087.001 T1486 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1021 T1486 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1486 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1071.001 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1486 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1071.002 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1071.001 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1071.001 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1070.004 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 | Mapped |