Linux Process Execution of esxcli vsan for Virtual Storage Information Discovery
Flags Linux executions of /esxcli with the vsan namespace and get/list subcommands to enumerate virtual storage.
FreeUnreviewedSigmamediumv1
linux-process-execution-of-esxcli-vsan-for-virtual-storage-information-discovery-d54c2f06
title: Linux Process Execution of esxcli vsan for Virtual Storage Information Discovery
id: 8f90b914-47ce-412e-bbf4-5a7dad5cd2bb
status: test
description: This rule identifies Linux process executions where the command line contains "vsan" and "esxcli" (with the process image path ending in /esxcli), along with additional subcommands such as "get" or "list". Attackers can use ESXi management tooling to enumerate virtual storage details, supporting discovery and subsequent targeting or abuse. It relies on process creation telemetry capturing the executable path and command-line arguments.
references:
- https://www.trendmicro.com/en_us/research/21/e/darkside-linux-vms-targeted.html
- https://www.trendmicro.com/en_us/research/22/a/analysis-and-Impact-of-lockbit-ransomwares-first-linux-and-vmware-esxi-variant.html
- https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vsan.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_vsan_discovery.yml
author: Nasreddine Bencherchali (Nextron Systems), Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
- attack.discovery
- attack.execution
- attack.t1033
- attack.t1007
- attack.t1059.012
logsource:
category: process_creation
product: linux
detection:
selection_img:
Image|endswith: /esxcli
CommandLine|contains: vsan
selection_cli:
CommandLine|contains:
- " get"
- " list"
condition: all of selection_*
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: d54c2f06-aca9-4e2b-81c9-5317858f4b79
type: derived
What it detects
This rule identifies Linux process executions where the command line contains "vsan" and "esxcli" (with the process image path ending in /esxcli), along with additional subcommands such as "get" or "list". Attackers can use ESXi management tooling to enumerate virtual storage details, supporting discovery and subsequent targeting or abuse. It relies on process creation telemetry capturing the executable path and command-line arguments.
Known false positives
- Legitimate administration activities
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.