Techniques › T1570 › AN0519
AN0519 Analytic 0519
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Identify lateral transfer via datastore file uploads or internal scp/ssh sessions that result in new VMX/VMDK or script files. Correlate transfer with VM execution or datastore modification.</p>
- Detects
- T1570 Lateral Tool Transfer
- Part of
- DET0183 Detection Strategy for Lateral Tool Transfer across OS platforms
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:vmkernel | Upload of file to datastore | DC0059 File Metadata |
| esxi:hostd | scp/ssh used to move file across hosts | DC0064 Command Execution |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
DatastoreWhitelist | Known authorized paths for legitimate VM operations |
TransferProtocol | Protocols allowed for intra-VM host transfers |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2024-4577 | PHP Group PHP | Mapped |