kevmap

TechniquesT1071.001 › AN0078

AN0078 Analytic 0078

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.</p>
Detects
T1071.001 Web Protocols
Part of
DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
NSM:FlowSPAN or port-mirrored HTTP/SDC0085 Network Traffic Content
esxi:shell/root/.ash_history or /etc/init.d/*DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ShellScriptMatchMatch on commands like `wget https://*`, `curl -s`
ExternalConnectionFilterPublic IPs or external DNS hostnames

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-4324Adobe Acrobat and ReaderMapped
CVE-2015-3113Adobe Flash PlayerMapped
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4978Justice AV Solutions Viewer Mapped