Techniques › T1059 › AN1431
AN1431 Analytic 1431
ESXi · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly.</p>
- Detects
- T1059 Command and Scripting Interpreter
- Part of
- DET0516 Behavioral Detection of Command and Scripting Interpreter Abuse
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| esxi:vobd | shell session start | DC0064 Command Execution |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ShellEnabledFlag | Control alerting based on whether ESXi shell access is typically disabled. |
SSHContext | Scope detection to SSH session origins or internal vs. remote access. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2010-2883 | Adobe Acrobat and Reader | Mapped |
| CVE-2016-4437 | Apache Shiro | Mapped |
| CVE-2017-11882 | Microsoft Office | Mapped |
| CVE-2017-5638 | Apache Struts | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | Mapped |
| CVE-2017-9805 | Apache Struts | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | Mapped |
| CVE-2018-11776 | Apache Struts | Mapped |
| CVE-2018-6789 | Exim Exim | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | Mapped |
| CVE-2019-17558 | Apache Solr | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Mapped |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center | Mapped |
| CVE-2020-0787 | Microsoft Windows | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | Mapped |
| CVE-2020-17530 | Apache Struts | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |
| CVE-2020-5902 | F5 BIG-IP | Stale |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | Mapped |
| CVE-2021-21972 | VMware vCenter Server | Mapped |
| CVE-2021-22005 | VMware vCenter Server | Mapped |
| CVE-2021-22204 | Perl Exiftool | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | Mapped |
| CVE-2021-27101 | Accellion FTA | Mapped |
| CVE-2021-27102 | Accellion FTA | Mapped |
| CVE-2021-27104 | Accellion FTA | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | Mapped |
| CVE-2021-3129 | Laravel Ignition | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | Mapped |
| CVE-2021-41773 | Apache HTTP Server | Mapped |
| CVE-2021-42013 | Apache HTTP Server | Mapped |
| CVE-2021-42237 | Sitecore XP | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | Mapped |
| CVE-2021-42321 | Microsoft Exchange | Mapped |
| CVE-2021-45046 | Apache Log4j2 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | Mapped |
| CVE-2022-1040 | Sophos Firewall | Mapped |
| CVE-2022-21971 | Microsoft Windows | Mapped |
| CVE-2022-21999 | Microsoft Windows | Mapped |
| CVE-2022-22047 | Microsoft Windows | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | Mapped |
| CVE-2022-22965 | VMware Spring Framework | Mapped |
| CVE-2022-23131 | Zabbix Frontend | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | Mapped |
| CVE-2022-24521 | Microsoft Windows | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | Mapped |
| CVE-2022-29303 | SolarView Compact | Mapped |
| CVE-2022-34713 | Microsoft Windows | Mapped |
| CVE-2022-35405 | Zoho ManageEngine | Mapped |
| CVE-2022-35914 | Teclib GLPI | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | Mapped |
| CVE-2022-37969 | Microsoft Windows | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | Mapped |
| CVE-2022-41125 | Microsoft Windows | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | Mapped |
| CVE-2023-20867 | VMware Tools | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | Stale |
| CVE-2023-2533 | PaperCut NG/MF | Mapped |
| CVE-2023-26359 | Adobe ColdFusion | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | Mapped |
| CVE-2023-28252 | Microsoft Windows | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | Mapped |
| CVE-2023-33246 | Apache RocketMQ | Mapped |
| CVE-2023-33538 | TP-Link Multiple Routers | Mapped |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2023-36845 | Juniper Junos OS | Mapped |
| CVE-2023-36846 | Juniper Junos OS | Mapped |
| CVE-2023-36847 | Juniper Junos OS | Mapped |
| CVE-2023-36851 | Juniper Junos OS | Mapped |
| CVE-2023-38035 | Ivanti Sentry | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | Mapped |
| CVE-2023-43770 | Roundcube Webmail | Mapped |
| CVE-2023-48365 | Qlik Sense | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | Mapped |
| CVE-2024-11182 | MDaemon Email Server | Mapped |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | Mapped |
| CVE-2024-12987 | DrayTek Vigor Routers | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |
| CVE-2024-20399 | Cisco NX-OS | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | Mapped |
| CVE-2024-26169 | Microsoft Windows | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | Mapped |
| CVE-2024-29059 | Microsoft .NET Framework | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2024-38475 | Apache HTTP Server | Mapped |
| CVE-2024-41710 | Mitel SIP Phones | Mapped |
| CVE-2024-45195 | Apache OFBiz | Mapped |
| CVE-2024-4577 | PHP Group PHP | Mapped |
| CVE-2024-4671 | Google Chromium | Mapped |
| CVE-2024-4761 | Google Chromium V8 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-4885 | Progress WhatsUp Gold | Mapped |
| CVE-2024-4947 | Google Chromium V8 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-53104 | Linux Kernel | Mapped |
| CVE-2024-53197 | Linux Kernel | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | Mapped |
| CVE-2024-57968 | Advantive VeraCore | Mapped |
| CVE-2024-58136 | Yiiframework Yii | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | Mapped |
| CVE-2025-0994 | Trimble Cityworks | Mapped |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | Mapped |
| CVE-2025-20281 | Cisco Identity Services Engine | Mapped |
| CVE-2025-20337 | Cisco Identity Services Engine | Mapped |
| CVE-2025-21590 | Juniper Junos OS | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | Mapped |
| CVE-2025-24085 | Apple Multiple Products | Mapped |
| CVE-2025-24201 | Apple Multiple Products | Mapped |
| CVE-2025-24985 | Microsoft Windows | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | Mapped |
| CVE-2025-30397 | Microsoft Windows | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | Mapped |
| CVE-2025-31200 | Apple Multiple Products | Stale |
| CVE-2025-31201 | Apple Multiple Products | Stale |
| CVE-2025-31324 | SAP NetWeaver | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | Mapped |
| CVE-2025-3248 | Langflow Langflow | Mapped |
| CVE-2025-32701 | Microsoft Windows | Mapped |
| CVE-2025-32706 | Microsoft Windows | Mapped |
| CVE-2025-32709 | Microsoft Windows | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | Mapped |
| CVE-2025-33053 | Microsoft Windows | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | Mapped |
| CVE-2025-3928 | Commvault Web Server | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | Mapped |
| CVE-2025-42999 | SAP NetWeaver | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | Mapped |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | Mapped |
| CVE-2025-6554 | Google Chromium V8 | Mapped |