Linux Process Monitoring: ESXi VM Discovery via esxcli vm process list

Alerts on Linux process executions of /esxcli with command-line arguments indicating VM discovery (vm process ... list).

FreeUnreviewedSigmamediumv1
title: "Linux Process Monitoring: ESXi VM Discovery via esxcli vm process list"
id: 125ebb4a-5496-47ad-82c7-e636616477c4
status: test
description: 'This rule flags execution of the esxcli binary with arguments that match VMware ESXi VM information discovery: "vm process" and a command ending with " list". Attackers may use this to enumerate virtual machines before targeting them for disruption or further exploitation. The detection relies on process creation telemetry, specifically the executed binary path ending in /esxcli and the command-line content that includes the vm process list pattern.'
references:
  - https://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
  - https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vm.html
  - https://www.secuinfra.com/en/techtalk/hide-your-hypervisor-analysis-of-esxiargs-ransomware/
  - https://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_discovery.yml
author: Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
  - attack.discovery
  - attack.execution
  - attack.t1033
  - attack.t1007
  - attack.t1059.012
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|endswith: /esxcli
    CommandLine|contains: vm process
    CommandLine|endswith: " list"
  condition: selection
falsepositives:
  - Legitimate administration activities
level: medium
license: DRL-1.1
related:
  - id: 5f1573a7-363b-4114-9208-ad7a61de46eb
    type: derived

What it detects

This rule flags execution of the esxcli binary with arguments that match VMware ESXi VM information discovery: "vm process" and a command ending with " list". Attackers may use this to enumerate virtual machines before targeting them for disruption or further exploitation. The detection relies on process creation telemetry, specifically the executed binary path ending in /esxcli and the command-line content that includes the vm process list pattern.

Known false positives

  • Legitimate administration activities

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.