Tag
high
advisory
Windows EventLog Security Descriptor Tampering
2 rules 1 TTPThis analytic detects suspicious modifications to the EventLog security descriptor registry value, specifically the 'CustomSD' value, within the registry path 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\<Channel>\CustomSD', which can be used for defense evasion by attackers.
Sysmon +3
defense-evasion
eventlog
registry
tampering
2r
1t
high
advisory
ESXi VIB Acceptance Level Tampering Detection
2 rulesThis detection identifies changes to the VIB (vSphere Installation Bundle) acceptance level on an ESXi host, potentially allowing the installation of unsigned or unverified software and lowering the system's integrity enforcement.
ESXi +3
vmware
vib
tampering
post-compromise
ransomware
2r
high
advisory
ESXi Loghost Configuration Tampering
2 rules 1 TTPAn attacker modifies the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response.
ESXi +3
syslog
loghost
tampering
defense-evasion
2r
1t