Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0232 — Detection Strategy for ESXi Administration Command
DET0232

Detection Strategy for ESXi Administration Command

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0646 Analytic 0646
ESXi

Detects anomalous usage of ESXi Guest Operations APIs such as StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, or InitiateFileTransferFromGuest. Defender perspective focuses on unusual frequency of guest API calls, invocation from unexpected management accounts, or execution outside of business hours. These correlated signals indicate adversarial abuse of ESXi administrative services to run commands on guest VMs.

esxi:hostd Guest Operations API invocation: StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, InitiateFileTransferFromGuest
[ExpectedAdminUsers] Whitelist of management accounts authorized to use ESXi Guest Ops APIs.
[TimeWindow] Business hours during which Guest Ops API usage is expected; activity outside may be suspicious.
[OperationThreshold] Number of Guest Ops API calls considered anomalous if exceeded in a given timeframe.
[AuthorizedVMs] List of VMs where Guest Ops usage is permitted; usage on other VMs may indicate malicious activity.

Detected Techniques

1

Details

MITRE ID
DET0232
STIX ID
x-mitre-detection-strategy--c1d8aa38-aefb-4ea8-8c80-2dfa05eaaecb
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.