
Summary
This rule detects the ESXi host activity where the esxcli vm process list command is observed in vSphere logs. The command enumerates running virtual machines and the world IDs associated with their vmx processes. Those world IDs can be used by a subsequent kill operation to stop VMs and release locks on their virtual disks (vmdk). The rule targets legitimate process-discovery activity on ESXi hosts but can indicate attacker reconnaissance or ransomware-like behavior if followed by disruptive commands. It relies on Elastics’s vSphere integration data and surfaces when the message contains both esxcli and vm process list. The rule is categorized as Discovery with a low severity, given the potential for legitimate administration during maintenance. False positives include administrators listing VMs during maintenance without following up with destructive actions. The MITRE ATT&CK mapping is T1057 (Process Discovery), under the Discovery tactic TA0007. If the same session subsequently executes commands such as pkill, power.off, or manipulates snapshots or vmdk files, this may indicate adversarial follow-on activity; triage should focus on session context and correlation with related host changes. Response steps include isolating the host if the same session kills VMs or removes critical snapshots; otherwise, log the account and source for follow-up hunting across hosts. Setup requires enabling ESXi host logs via the Elastic vSphere integration. This rule supports detection of targeted or opportunistic discovery activity by adversaries seeking to map virtual environments before disruption or data exfiltration. Reference investigations and guidance are provided in the rule’s associated analysis and references, including links to ESXi security write-ups and detection opportunities.
Categories
- Infrastructure
- On-Premise
Data Sources
- Process
ATT&CK Techniques
- T1057
Created: 2026-09-30