
Summary
Detects obfuscated ESXi shell commands reconstructed via encoding (octal, hex, chr(), awk %c sequences, reversed strings, and invisible Unicode) in vSphere logs. The decoding typically reveals actions that can impact host security, such as resetting syslog, altering firewall rules, or terminating or listing VMs. The rule searches vsphere.log for patterns suggesting obfuscation (e.g., chr(101), %c sequences, hex bytes, escaped \x sequences, or zero-width characters that spell esx) and emits a high-severity alert with context for incident response. MITRE ATT&CK mappings include T1027 (Obfuscated/Compressed Files or Information) under Defense Evasion and T1059 (Command and Scripting Interpreter) with the Unix Shell subtechnique for execution. The rule includes setup prerequisites, investigation steps, remediation guidance, and false-positive considerations to help responders determine whether an encoded command is malicious.
Categories
- On-Premise
- Infrastructure
- Endpoint
Data Sources
- File
- Application Log
ATT&CK Techniques
- T1027
- T1059
- T1059.004
Created: 2026-09-30