kevmap

Log sources › esxi:auth

esxi:auth

Inverted view: what can be detected if this is the log you have. ESXi

6
channels
6
analytics
6
techniques
15
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/auth.log DC0002 User Account Authentication AN1286 1
None DC0088 Logon Session Metadata AN1640 1
SSH session/login DC0002 User Account Authentication AN1537 1
Shell login or escalation DC0067 Logon Session Creation AN1083 1
interactive shell or SSH access preceding storage enumeration DC0002 User Account Authentication AN0539 1
user session DC0034 Process Metadata AN0098 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.004 SSHlateral movement52
T1057 Process Discoverydiscovery80
T1059.004 Unix Shellexecution1814
T1059.012 Hypervisor CLIexecution90
T1078.001 Default Accountsstealth, persistence, privilege escalation, initial access40
T1680 Local Storage Discoverydiscovery00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2023-38831RARLAB WinRAR T1059.004 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1059.004 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 Mapped
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped