Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0535 — Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access
DET0535

Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1475 Analytic 1475
ESXi

Malicious VIB installation for persistence via `esxcli software vib install` using `--force` or `--no-sig-check`, enabling custom startup scripts or firewall rules. Behavior chain: (1) unsigned/suspicious VIB installation → (2) startup script or binary placed in persistent boot path → (3) persistence across reboot via /etc/rc.local.d or other boot hook).

esxi:esxupdate /var/log/esxupdate.log contains VIB installed with `--force` or `--no-sig-check` and non-standard acceptance levels esxi:shell `esxcli software vib install` with `--force` or `--no-sig-check` from shell history or `shell.log` linux:fim Changes to /etc/rc.local.d/local.sh or creation of unexpected startup files in persistent partitions (/etc/init.d, /store, /locker)
[AcceptanceLevel] Some environments may intentionally permit CommunitySupported or unsigned VIBs—filter by known allowed publishers.
[InstallCommandThreshold] Set alerting thresholds for frequency of VIB install attempts per host/user/time window.
[StartupPathRegex] Tune regex for monitoring startup file locations based on ESXi image customization.

Detected Techniques

1

Details

MITRE ID
DET0535
STIX ID
x-mitre-detection-strategy--000d7b6f-0bb5-4144-a3eb-1aa822433da1
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.