Techniques
Sample rules
ESXi Shell Command Obfuscation
- source: elastic
- technicques:
- T1027
- T1059
Description
Detects ESXi shell commands that rebuild a command with encoding instead of writing it in clear text, including
octal and hex printf, Python chr(), awk %c sequences, reversed strings, and invisible Unicode. The shell
log then hides the administrative command. The decoded action can still change syslog, the firewall, or other
host settings.
Detection logic
data_stream.dataset: "vsphere.log" and (
message: (
"chr(101)" or
"%c%c%c%c%c%c" or
"ilcxse" or
"0xe2,0x80,0x8b" or
"0xf3,0xb0,0x80,0x80" or
"\\x65\\x73\\x78" or
"\\145\\163\\170"
)
)