1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1505.006 vSphere Installation Bundles — Attack Simulation

Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system management in VMware environments. Since ESXi uses an in-memory filesystem where changes made to most files are stored in RAM rather than in persistent storage, these modifications are lost after a reboot. However, VIBs can be used to create startup tasks,…

Technique description

Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system management in VMware environments. Since ESXi uses an in-memory filesystem where changes made to most files are stored in RAM rather than in persistent storage, these modifications are lost after a reboot. However, VIBs can be used to create startup tasks,…

No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.

Connected ecosystem references

Linked tags

Detection and collection

T1505.006 detection workspace

Attack tools

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.