kevmap

TechniquesT1059 › AN1431

AN1431 Analytic 1431

ESXi · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly.</p>
Detects
T1059 Command and Scripting Interpreter
Part of
DET0516 Behavioral Detection of Command and Scripting Interpreter Abuse

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
esxi:vobdshell session startDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ShellEnabledFlagControl alerting based on whether ESXi shell access is typically disabled.
SSHContextScope detection to SSH session origins or internal vs. remote access.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-2883Adobe Acrobat and ReaderMapped
CVE-2016-4437Apache ShiroMapped
CVE-2017-11882Microsoft OfficeMapped
CVE-2017-5638Apache StrutsMapped
CVE-2017-6742Cisco IOS and IOS XE SoftwareMapped
CVE-2017-9805Apache StrutsMapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN)Mapped
CVE-2018-11776Apache StrutsMapped
CVE-2018-6789Exim EximMapped
CVE-2018-7600Drupal Drupal CoreMapped
CVE-2019-11510Ivanti Pulse Connect SecureMapped
CVE-2019-11580Atlassian Crowd and Crowd Data CenterMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2019-17558Apache SolrMapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2019-3398Atlassian Confluence Server and Data CenterMapped
CVE-2020-0787Microsoft WindowsMapped
CVE-2020-15505Ivanti MobileIron Multiple ProductsMapped
CVE-2020-17530Apache StrutsMapped
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-29557D-Link DIR-825 R1 DevicesMapped
CVE-2020-29574Sophos CyberoamOSMapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8515DrayTek Multiple Vigor RoutersMapped
CVE-2021-1497Cisco HyperFlex HXMapped
CVE-2021-1498Cisco HyperFlex HXMapped
CVE-2021-20035SonicWall SMA100 AppliancesMapped
CVE-2021-21972VMware vCenter ServerMapped
CVE-2021-22005VMware vCenter ServerMapped
CVE-2021-22204Perl ExiftoolMapped
CVE-2021-22205GitLab Community and Enterprise EditionsMapped
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-22894Ivanti Pulse Connect SecureMapped
CVE-2021-22900Ivanti Pulse Connect SecureMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26084Atlassian Confluence Server and Data CenterMapped
CVE-2021-27101Accellion FTAMapped
CVE-2021-27102Accellion FTAMapped
CVE-2021-27104Accellion FTAMapped
CVE-2021-31166Microsoft HTTP Protocol StackMapped
CVE-2021-3129Laravel IgnitionMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-35464ForgeRock Access Management (AM)Mapped
CVE-2021-41773Apache HTTP ServerMapped
CVE-2021-42013Apache HTTP ServerMapped
CVE-2021-42237Sitecore XPMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-42321Microsoft ExchangeMapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2021-45382D-Link Multiple RoutersMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-21971Microsoft WindowsMapped
CVE-2022-21999Microsoft WindowsMapped
CVE-2022-22047Microsoft WindowsMapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2022-22965VMware Spring FrameworkMapped
CVE-2022-23131Zabbix FrontendMapped
CVE-2022-23748Audinate Dante DiscoveryMapped
CVE-2022-24521Microsoft WindowsMapped
CVE-2022-26258D-Link DIR-820LMapped
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped
CVE-2022-29303SolarView CompactMapped
CVE-2022-34713Microsoft WindowsMapped
CVE-2022-35405Zoho ManageEngineMapped
CVE-2022-35914Teclib GLPIMapped
CVE-2022-36804Atlassian Bitbucket Server and Data CenterMapped
CVE-2022-37969Microsoft WindowsMapped
CVE-2022-39197Fortra Cobalt StrikeMapped
CVE-2022-41125Microsoft WindowsMapped
CVE-2022-42948Fortra Cobalt StrikeMapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2023-20109Cisco IOS and IOS XEMapped
CVE-2023-20118Cisco Small Business RV Series RoutersMapped
CVE-2023-20273Cisco Cisco IOS XE Web UIMapped
CVE-2023-20867VMware ToolsMapped
CVE-2023-20887VMware Aria Operations for NetworksMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2023-2533PaperCut NG/MFMapped
CVE-2023-26359Adobe ColdFusionMapped
CVE-2023-27350PaperCut MF/NGMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) ApplianceMapped
CVE-2023-33246Apache RocketMQMapped
CVE-2023-33538TP-Link Multiple RoutersMapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS)Mapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-36845Juniper Junos OSMapped
CVE-2023-36846Juniper Junos OSMapped
CVE-2023-36847Juniper Junos OSMapped
CVE-2023-36851Juniper Junos OSMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2023-40044Progress WS_FTP ServerMapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business SecurityMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-48365Qlik SenseMapped
CVE-2023-48788Fortinet FortiClient EMSMapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcelMapped
CVE-2024-11182MDaemon Email ServerMapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)Mapped
CVE-2024-12987DrayTek Vigor RoutersMapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20399Cisco NX-OSMapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM)Mapped
CVE-2024-21413Microsoft Office OutlookMapped
CVE-2024-21887Ivanti Connect Secure and Policy SecureMapped
CVE-2024-26169Microsoft WindowsMapped
CVE-2024-27198JetBrains TeamCityMapped
CVE-2024-29059Microsoft .NET FrameworkMapped
CVE-2024-34102Adobe Commerce and Magento Open SourceMapped
CVE-2024-38475Apache HTTP ServerMapped
CVE-2024-41710Mitel SIP PhonesMapped
CVE-2024-45195Apache OFBizMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4761Google Chromium V8Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-4885Progress WhatsUp GoldMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-50603Aviatrix ControllersMapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-53104Linux KernelMapped
CVE-2024-53197Linux KernelMapped
CVE-2024-56145Craft CMS Craft CMSMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2024-57968Advantive VeraCoreMapped
CVE-2024-58136Yiiframework YiiMapped
CVE-2024-6047GeoVision Multiple DevicesMapped
CVE-2025-0994Trimble CityworksMapped
CVE-2025-1976Broadcom Brocade Fabric OSMapped
CVE-2025-20281Cisco Identity Services EngineMapped
CVE-2025-20337Cisco Identity Services EngineMapped
CVE-2025-21590Juniper Junos OSMapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-23006SonicWall SMA1000 AppliancesMapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-24085Apple Multiple ProductsMapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-24985Microsoft WindowsMapped
CVE-2025-27038Qualcomm Multiple ChipsetsMapped
CVE-2025-30397Microsoft WindowsMapped
CVE-2025-30406Gladinet CentreStackMapped
CVE-2025-31161CrushFTP CrushFTPMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale
CVE-2025-31324SAP NetWeaverMapped
CVE-2025-32433Erlang Erlang/OTPMapped
CVE-2025-3248Langflow LangflowMapped
CVE-2025-32701Microsoft WindowsMapped
CVE-2025-32706Microsoft WindowsMapped
CVE-2025-32709Microsoft WindowsMapped
CVE-2025-32756Fortinet Multiple ProductsMapped
CVE-2025-33053Microsoft WindowsMapped
CVE-2025-35939Craft CMS Craft CMSMapped
CVE-2025-3928Commvault Web ServerMapped
CVE-2025-3935ConnectWise ScreenConnectMapped
CVE-2025-42599Qualitia Active! MailMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4632Samsung MagicINFO 9 ServerMapped
CVE-2025-47812Wing FTP Server Wing FTP ServerMapped
CVE-2025-53770Microsoft SharePointMapped
CVE-2025-6543Citrix NetScaler ADC and GatewayMapped
CVE-2025-6554Google Chromium V8Mapped