Techniques
Sample rules
ESXi Virtual Machine Process List
- source: elastic
- technicques:
- T1057
Description
Detects esxcli vm process list on an ESXi host. The command lists running virtual machines and the world IDs of
their vmx processes. Those IDs are what a later kill command uses to stop the VMs and release the locks on their
virtual disks.
Detection logic
data_stream.dataset: "vsphere.log" and event.module: "vsphere" and message: ("esxcli" and "vm process list")