Techniques
Sample rules
Devcon Execution Disabling VMware VMCI Device
- source: sigma
- technicques:
- t1543
- t1543.003
- t1562
- t1562.001
Description
Detects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device. This can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device. This has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.
Detection logic
condition: all of selection_*
selection_action:
CommandLine|contains: ' disable '
selection_img:
- Image|endswith: \devcon.exe
- OriginalFileName: DevCon.exe
selection_vmci_pci:
CommandLine|contains:
- 15AD&DEV_0740
- VMWVMCIHOSTDEV