Back to results

ESXi Virtual Machine Process List

Detects `esxcli vm process list` on an ESXi host. The command lists running virtual machines and the world IDs of their `vmx` processes. Those IDs are what a later kill command uses to stop the VMs and release the…

Description

Detects `esxcli vm process list` on an ESXi host. The command lists running virtual machines and the world IDs of their `vmx` processes. Those IDs are what a later kill command uses to stop the VMs and release the locks on their virtual disks.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ESXiLinuxmacOSNetwork DevicesWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source category
event_index

Known benign triggers

  • Administrators list virtual machines during maintenance and troubleshooting. Review whether the same session then kills those processes or searches the datastore.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice