Techniques › T1090.004 › AN0567
AN0567 Analytic 0567
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Traffic originating from ESXi hosts or management interfaces displays SNI-to-Host mismatch behavior, particularly anomalous given typical infrastructure communication patterns.</p>
- Detects
- T1090.004 Domain Fronting
- Part of
- DET0196 Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| NSM:Firewall | TLS/HTTP inspection | DC0085 Network Traffic Content |
| esxi:shell | /var/log/vmkernel.log, /var/log/vmkwarning.log | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AdminPortAccess | ESXi hosts should rarely initiate external HTTPS—threshold to alert. |
TLSHandshakeOutliers | Define entropy or timing anomalies for TLS handshake. |
DomainMismatchThreshold | SNI/Host mismatch occurrence tolerance. |