kevmap

Log sources › esxcli:network

esxcli:network

Inverted view: what can be detected if this is the log you have. ESXi

4
channels
4
analytics
4
techniques
4
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Socket inspection showing RSA key exchange outside baseline endpoints DC0085 Network Traffic Content AN1499 1
Socket sessions with randomized payloads inconsistent with TLS DC0085 Network Traffic Content AN0403 1
listening sockets bound to non-standard ports DC0085 Network Traffic Content AN0636 1
listening sockets bound with non-standard encapsulated protocols DC0085 Network Traffic Content AN1486 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-40449Microsoft Windows T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1573.001 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1573.001 Mapped
CVE-2023-38035Ivanti Sentry T1571 Mapped