LoFP LoFP / administrators run these commands during inventory, troubleshooting, and support. review whether the same session continues into virtual machine shutdown, snapshot removal, or a datastore search.

Techniques

Sample rules

ESXi System and Account Enumeration

Description

Detects shell commands that collect ESXi host details or the local account list, including uname -a, system version, hostname, and esxcli system account list. The output identifies the build and the accounts that can log in. Listing accounts shows which identities exist before one of them is changed or used.

Detection logic

data_stream.dataset: "vsphere.log" and event.module: "vsphere" and 
message: (
  "uname -a" or
  "esxcli system version get" or
  "esxcli system hostname get" or
  "esxcli system account list"
)