Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0558 — Detection Strategy for ESXi Hypervisor CLI Abuse
DET0558

Detection Strategy for ESXi Hypervisor CLI Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1537 Analytic 1537
ESXi

Detects suspicious use of ESXi native CLI tools like esxcli and vim-cmd by unauthorized users or outside expected maintenance windows. Focus is on actions such as stopping VMs, reconfiguring network/firewall settings, and enabling SSH or logging.

esxi:vmkernel esxcli, vim-cmd invocation esxi:auth SSH session/login
[TimeWindow] Helps scope detection to off-hours or change control gaps.
[UserContext] Environment-specific users may run these commands as part of normal ops.
[CommandPattern] CLI commands vary by adversary intent (e.g., 'stop', 'reboot', 'firewall set')

Detected Techniques

1

Details

MITRE ID
DET0558
STIX ID
x-mitre-detection-strategy--5307b508-28e8-44c6-9487-212ccd3ab86c
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.