kevmap

TechniquesT1036 › AN0359

AN0359 Analytic 0359

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary places scripts or binaries with misleading names in /etc/rc.local.d or /var/spool/cron, or registers services with legitimate-sounding names not present in default ESXi builds.</p>
Detects
T1036 Masquerading
Part of
DET0127 Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:hostdregisters services with legitimate-sounding namesDC0041 Service Metadata
esxi:shellscripts or binaries with misleading namesDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ServiceNameBaselineTune based on default service names vs. suspicious new entries
ScriptFilePathWatch for new binaries/scripts in boot or cron folders
ExecutionContextDetermine if execution happens at boot or scheduled interval

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped