Linux ESXi esxcli Storage Information Discovery via esxcli storage commands
Flags Linux process executions of esxcli with storage discovery subcommands like get/list.
- Product
- linux
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), Cedric Maurugeon (SigmaHQ), DRL 1.1
- Published
- 2023-09-04
- Updated
- 2026-07-31
ATT&CK techniques
Execution → DiscoveryRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule detects process executions where the command line includes the esxcli storage-related arguments and requests storage information (e.g., get/list). Attackers often use VMware ESXi command-line utilities to inventory storage configuration and status as part of discovery before further actions. Telemetry relies on process creation events from Linux that include the executed binary path and the full command line.
Reporting behind it
- trendmicro.comhttps://www.trendmicro.com/en_us/research/21/e/darkside-linux-vms-targeted.html
- trendmicro.comhttps://www.trendmicro.com/en_us/research/22/a/analysis-and-Impact-of-lockbit-ransomwares-first-linux-and-vmware-esxi-variant.html
- developer.broadcom.comhttps://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_storage.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_storage_discovery.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux ESXi esxcli Storage Information Discovery via esxcli storage commands
id: f046022c-2ac3-4619-bc95-953123faca83
status: test
description: This rule detects process executions where the command line includes the esxcli storage-related arguments and requests storage information (e.g., get/list). Attackers often use VMware ESXi command-line utilities to inventory storage configuration and status as part of discovery before further actions. Telemetry relies on process creation events from Linux that include the executed binary path and the full command line.
references:
- https://www.trendmicro.com/en_us/research/21/e/darkside-linux-vms-targeted.html
- https://www.trendmicro.com/en_us/research/22/a/analysis-and-Impact-of-lockbit-ransomwares-first-linux-and-vmware-esxi-variant.html
- https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_storage.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_storage_discovery.yml
author: Nasreddine Bencherchali (Nextron Systems), Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
- attack.discovery
- attack.execution
- attack.t1033
- attack.t1007
- attack.t1059.012
logsource:
category: process_creation
product: linux
detection:
selection_img:
Image|endswith: /esxcli
CommandLine|contains: storage
selection_cli:
CommandLine|contains:
- " get"
- " list"
condition: all of selection_*
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: f41dada5-3f56-4232-8503-3fb7f9cf2d60
type: derived