// MITRE ATT&CK

T1505.006 · vSphere Installation Bundles

🎯 Persistence ESXi Sub-technique

Sub-technique of T1505 · Server Software Component.

Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system management in VMware environments. Since ESXi uses an in-memory filesystem where changes made to most files ar...

How to detect & mitigate it

Detecting vSphere Installation Bundles starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.