Back to results

ESXi System and Account Enumeration

Detects shell commands that collect ESXi host details or the local account list, including `uname -a`, system version, hostname, and `esxcli system account list`. The output identifies the build and the accounts that…

Description

Detects shell commands that collect ESXi host details or the local account list, including `uname -a`, system version, hostname, and `esxcli system account list`. The output identifies the build and the accounts that can log in. Listing accounts shows which identities exist before one of them is changed or used.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source category
event_index

Known benign triggers

  • Administrators run these commands during inventory, troubleshooting, and support. Review whether the same session continues into virtual machine shutdown, snapshot removal, or a datastore search.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice