Linux Process Execution of esxcli VM Listing Commands
Alerts on Linux process executions of /esxcli with command-line arguments indicating VM discovery (vm process ... list).
- Product
- linux
- Category
- process_creation
- Author
- Cedric Maurugeon (SigmaHQ), DRL 1.1
- Published
- 2023-09-04
- Updated
- 2026-07-31
ATT&CK techniques
Execution → DiscoveryRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies execution of the esxcli utility on Linux when command-line arguments indicate VM information retrieval. The pattern matches processes invoking esxcli with VM-related subcommands, which can support discovery and mapping of virtual infrastructure. It relies on process creation telemetry, including the executable path and command-line content.
Reporting behind it
- crowdstrike.comhttps://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
- developer.broadcom.comhttps://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vm.html
- secuinfra.comhttps://www.secuinfra.com/en/techtalk/hide-your-hypervisor-analysis-of-esxiargs-ransomware/
- trendmicro.comhttps://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_discovery.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Process Execution of esxcli VM Listing Commands
id: 125ebb4a-5496-47ad-82c7-e636616477c4
status: test
description: This rule identifies execution of the esxcli utility on Linux when command-line arguments indicate VM information retrieval. The pattern matches processes invoking esxcli with VM-related subcommands, which can support discovery and mapping of virtual infrastructure. It relies on process creation telemetry, including the executable path and command-line content.
references:
- https://www.crowdstrike.com/blog/hypervisor-jackpotting-ecrime-actors-increase-targeting-of-esxi-servers/
- https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vm.html
- https://www.secuinfra.com/en/techtalk/hide-your-hypervisor-analysis-of-esxiargs-ransomware/
- https://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_discovery.yml
author: Cedric Maurugeon, Huntrule Team
date: 2023-09-04
tags:
- attack.discovery
- attack.execution
- attack.t1033
- attack.t1007
- attack.t1059.012
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: /esxcli
CommandLine|contains: vm process
CommandLine|endswith: " list"
condition: selection
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: 5f1573a7-363b-4114-9208-ad7a61de46eb
type: derived