Back to results

ESXi Virtual Machine Process Killed

Detects termination of a virtual machine process on an ESXi host, including `esxcli vm process kill`, `pkill` of `vmx` processes, and `vmdumper` suspend. A running VM holds a lock on its disks. Stopping the process…

Description

Detects termination of a virtual machine process on an ESXi host, including `esxcli vm process kill`, `pkill` of `vmx` processes, and `vmdumper` suspend. A running VM holds a lock on its disks. Stopping the process releases that lock and makes the disks writable.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ESXiIaaSLinuxmacOSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source category
event_index

Known benign triggers

  • Virtual machine process kills also happen during planned maintenance, host upgrades, and troubleshooting of a stuck VM. Confirm the world id, the account, and whether the same session also enumerates `/vmfs/volumes` or removes snapshots.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice