kevmap

Log sources › esxi:shell

esxi:shell

Inverted view: what can be detected if this is the log you have. ESXi

32
channels
37
analytics
36
techniques
47
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/root/.ash_history DC0064 Command Execution AN1172 1
/root/.ash_history or /etc/init.d/* DC0032 Process Creation AN0078 1
/var/log/shell.log DC0032 Process Creation
DC0040 File Deletion
AN0207 AN0395 AN0470 3
/var/log/shell.log entries containing "esxcli system clock get" DC0064 Command Execution AN0433 1
/var/log/vmkernel.log, /var/log/vmkwarning.log DC0032 Process Creation AN0567 1
CLI usage logs DC0064 Command Execution AN0727 1
Command execution trace DC0064 Command Execution AN0754 1
Execution of cat, tail, grep targeting /var/log/vmkernel.log or /var/log/hostd.log DC0064 Command Execution AN0709 1
None DC0029 Script Execution
DC0032 Process Creation
DC0064 Command Execution
AN0925 AN1018 AN1232 AN1640 4
Shell Access/Command Execution DC0064 Command Execution AN1043 1
Shell Execution DC0032 Process Creation AN0849 1
`esxcli software vib install` with `--force` or `--no-sig-check` from shell history or `shell.log` DC0064 Command Execution AN1475 1
admin command usage DC0061 File Modification AN0660 1
base64 or gzip use within shell session DC0064 Command Execution AN0305 1
command IN ("esxcli vm process list", "vim-cmd vmsvc/getallvms") DC0064 Command Execution AN0572 1
commands containing base64, openssl enc -base64, xxd -p DC0032 Process Creation AN0348 1
commands containing long non-standard tokens or custom lookup tables DC0032 Process Creation AN0930 1
esxcli software vib list DC0064 Command Execution AN1104 1
esxcli system shutdown or reboot invoked DC0064 Command Execution AN1541 1
esxcli system syslog config set --loghost='' or stopping hostd service DC0064 Command Execution AN0890 0
esxcli system syslog config set/reload, services.sh restart/stop DC0064 Command Execution AN2044 1
file write or edit DC0061 File Modification AN0353 1
interactive shell DC0064 Command Execution AN0098 1
invoked remote scripts (esxcli) DC0064 Command Execution AN0197 1
mv, rename, or chmod commands moving VM files into hidden directories DC0064 Command Execution AN1387 1
openssl|tar|dd DC0064 Command Execution AN0605 1
scripts or binaries with misleading names DC0064 Command Execution AN0359 1
shell command execution for chmod, chown, or file permission modification on VMFS or system files DC0064 Command Execution AN0837 1
shell command execution for system discovery (vim-cmd, esxcli, vmware-cmd) targeting VM inventory and host configuration DC0064 Command Execution AN1554 1
shell history DC0040 File Deletion AN0116 1
snapshot create/copy, esxcli DC0064 Command Execution AN0044 1
unset HISTFILE or HISTFILESIZE modifications DC0064 Command Execution AN1558 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1016.001 Internet Connection Discoverydiscovery00
T1021 Remote Serviceslateral movement114
T1021.004 SSHlateral movement52
T1036 Masqueradingstealth402
T1037.004 RC Scriptspersistence, privilege escalation00
T1057 Process Discoverydiscovery80
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1070.009 Clear Persistencestealth00
T1071.001 Web Protocolscommand and control4210
T1071.002 File Transfer Protocolscommand and control01
T1074 Data Stagedcollection20
T1074.001 Local Data Stagingcollection40
T1074.002 Remote Data Stagingcollection00
T1083 File and Directory Discoverydiscovery245
T1087.001 Local Accountdiscovery131
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.004 Domain Frontingcommand and control10
T1098.004 SSH Authorized Keyspersistence, privilege escalation01
T1124 System Time Discoverydiscovery30
T1132 Data Encodingcommand and control00
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1222 File and Directory Permissions Modificationdefense impairment21
T1480 Execution Guardrailsstealth00
T1486 Data Encrypted for Impactimpact1615
T1505.006 vSphere Installation Bundlespersistence00
T1518 Software Discoverydiscovery40
T1529 System Shutdown/Rebootimpact80
T1564 Hide Artifactsstealth100
T1654 Log Enumerationdiscovery00
T1673 Virtual Machine Discoverydiscovery00
T1685 Disable or Modify Toolsdefense impairment1640
T1690 Prevent Command History Loggingdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-3960Adobe BlazeDS T1486 Mapped
CVE-2009-4324Adobe Acrobat and Reader T1071.001 Mapped
CVE-2015-3113Adobe Flash Player T1071.001 Mapped
CVE-2015-5119Adobe Flash Player T1071.001 Mapped
CVE-2015-8651Adobe Flash Player T1486 Mapped
CVE-2016-1019Adobe Flash Player T1486 Mapped
CVE-2017-12637SAP NetWeaver T1083 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1083 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1486 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1083 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1486 Mapped
CVE-2020-5902F5 BIG-IP T1070.004 Stale
CVE-2021-22017VMware vCenter Server T1090.001 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1090 Mapped
CVE-2021-26855Microsoft Exchange Server T1090 Mapped
CVE-2021-34473Microsoft Exchange Server T1486 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1071.001 Mapped
CVE-2021-40449Microsoft Windows T1071.001 Mapped
CVE-2021-40539Zoho ManageEngine T1070.004 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1486 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1070.004 Mapped
CVE-2021-44228Apache Log4j2 T1486 Mapped
CVE-2021-45046Apache Log4j2 T1486 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1486 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-40684Fortinet Multiple Products T1098.004 Mapped
CVE-2022-42475Fortinet FortiOS T1071.001 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1486 Mapped
CVE-2023-22952SugarCRM Multiple Products T1070.004 T1083 Stale
CVE-2023-26360Adobe ColdFusion T1071.001 Mapped
CVE-2023-27532Veeam Backup & Replication T1087.001 T1486 Mapped
CVE-2023-28252Microsoft Windows T1021 T1486 Mapped
CVE-2023-36884Microsoft Windows T1486 Stale
CVE-2023-38035Ivanti Sentry T1071.001 Mapped
CVE-2023-38831RARLAB WinRAR T1486 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 Mapped
CVE-2023-40044Progress WS_FTP Server T1071.002 Mapped
CVE-2024-4577PHP Group PHP T1071.001 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1071.001 Mapped
CVE-2024-53704SonicWall SonicOS T1083 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 Mapped
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-32756Fortinet Multiple Products T1070.004 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 Mapped