kevmap

Log sources › esxi:cron

esxi:cron

Inverted view: what can be detected if this is the log you have. ESXi

3
channels
3
analytics
3
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
execution of scheduled job DC0001 Scheduled Job Creation AN0807 1
manual edits to /etc/rc.local.d/local.sh or cron.d DC0061 File Modification AN0262 1
process or cron activity DC0032 Process Creation AN0640 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.003 Cronexecution, persistence, privilege escalation60
T1104 Multi-Stage Channelscommand and control00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-38831RARLAB WinRAR T1053 Mapped
CVE-2024-4577PHP Group PHP T1053 Mapped