Server Software Component: vSphere Installation Bundles T1505.006

Tactic: Persistence

Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system management in VMware environments. Since ESXi uses an in-memory filesystem where changes made to most files are stored in RAM rather than in persistent storage, these modifications are lost after a reboot. However, VIBs can be used to create startup tasks, apply custom firewall rules, or deploy binaries that persist across reboots. Typically, administrators use VIBs for updates and system maintenance.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (2 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Message1contains 1 image profile bypassing signing and acceptance level..., image profile with validation disabled. , vib without valid signature,
sourcetype1in 1vmw-syslog, vmware:esxlog*

Top indicator values (5 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Messagecontains
image profile bypassing signing and acceptance level verification.
1
Messagecontains
image profile with validation disabled.
1
Messagecontains
vib without valid signature,
1
sourcetypein
vmw-syslog
123
sourcetypein
vmware:esxlog*
123

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Cross-platform

Domain: Endpoint

Splunk 1 rule