LoFP LoFP / administrators list virtual machines during maintenance and troubleshooting. review whether the same session then kills those processes or searches the datastore.

Techniques

Sample rules

ESXi Virtual Machine Process List

Description

Detects esxcli vm process list on an ESXi host. The command lists running virtual machines and the world IDs of their vmx processes. Those IDs are what a later kill command uses to stop the VMs and release the locks on their virtual disks.

Detection logic

data_stream.dataset: "vsphere.log" and event.module: "vsphere" and message: ("esxcli" and "vm process list")