Linux Process Monitoring: ESXi VM Discovery via esxcli vm process list
Alerts on Linux process executions of /esxcli with command-line arguments indicating VM discovery (vm process ... list).
FreeUnreviewedSigmamediumv1
linux-process-monitoring-esxi-vm-discovery-via-esxcli-vm-process-list-5f1573a7
title: "Linux Process Monitoring: ESXi VM Discovery via esxcli vm process list"
id: 125ebb4a-5496-47ad-82c7-e636616477c4
status: test
description: 'This rule flags execution of the esxcli binary with arguments that match VMware ESXi VM information discovery: "vm process" and a command ending with " list". Attackers may use this to enumerate virtual machines before targeting them for disruption or further exploitation. The detection relies on process creation telemetry, specifically the executed binary path ending in /esxcli and the command-line content that includes the vm process list pattern.'
references:
- https://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
- https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vm.html
- https://www.secuinfra.com/en/techtalk/hide-your-hypervisor-analysis-of-esxiargs-ransomware/
- https://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_discovery.yml
author: Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
- attack.discovery
- attack.execution
- attack.t1033
- attack.t1007
- attack.t1059.012
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: /esxcli
CommandLine|contains: vm process
CommandLine|endswith: " list"
condition: selection
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: 5f1573a7-363b-4114-9208-ad7a61de46eb
type: derived
What it detects
This rule flags execution of the esxcli binary with arguments that match VMware ESXi VM information discovery: "vm process" and a command ending with " list". Attackers may use this to enumerate virtual machines before targeting them for disruption or further exploitation. The detection relies on process creation telemetry, specifically the executed binary path ending in /esxcli and the command-line content that includes the vm process list pattern.
Known false positives
- Legitimate administration activities
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.