Linux Process Execution of esxcli Network Commands for ESXi Network Discovery
Alerts when an ESXi esxcli command queries or lists network configuration via the "network" flag.
- Product
- linux
- Category
- process_creation
- Author
- Cedric Maurugeon (SigmaHQ), DRL 1.1
- Published
- 2023-09-04
- Updated
- 2026-07-31
ATT&CK techniques
Execution → DiscoveryRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation on Linux where an executed binary path ends with /esxcli and the command line includes the network namespace. It specifically looks for esxcli subcommands that contain “ get” and “ list”, which are commonly used to retrieve network configuration details. This behavior matters because attackers can use ESXCLI to quickly enumerate network settings from an ESXi host. The detection relies on process creation telemetry, matching the executable path and command-line substrings.
Reporting behind it
- crowdstrike.comhttps://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
- developer.broadcom.comhttps://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_network.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_network_discovery.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Process Execution of esxcli Network Commands for ESXi Network Discovery
id: 8122da54-af19-450c-b1fb-6a364c572126
status: test
description: This rule flags process creation on Linux where an executed binary path ends with /esxcli and the command line includes the network namespace. It specifically looks for esxcli subcommands that contain “ get” and “ list”, which are commonly used to retrieve network configuration details. This behavior matters because attackers can use ESXCLI to quickly enumerate network settings from an ESXi host. The detection relies on process creation telemetry, matching the executable path and command-line substrings.
references:
- https://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
- https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_network.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_network_discovery.yml
author: Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
- attack.discovery
- attack.execution
- attack.t1033
- attack.t1007
- attack.t1059.012
logsource:
category: process_creation
product: linux
detection:
selection_img:
Image|endswith: /esxcli
CommandLine|contains: network
selection_cli:
CommandLine|contains:
- " get"
- " list"
condition: all of selection_*
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: 33e814e0-1f00-4e43-9c34-31fb7ae2b174
type: derived