heroui logo

ESXi Virtual Disk Files Enumerated

Elastic Detection Rules

View Source
Summary
Detects an ESXi shell search enumerating virtual disk and snapshot files (vmdk, vmsn, vmsd) under /vmfs/volumes on VMware ESXi hosts by observing vsphere.log entries that contain the path, a find command, and file extensions. The rule targets the exact host-side discovery step used by ransomware attackers to identify what to encrypt, without modifying files itself. It flags when a session lists guest disks, which could be followed by disruptive actions such as stopping VMs or deleting snapshots. The detection is designed to trigger in near real-time off logs from the Elastic vSphere integration and is mapped to MITRE ATT&CK T1083 (File and Directory Discovery) under the Discovery tactic. It includes triage guidance to correlate with subsequent VM/process actions and to distinguish benign admin tasks from malicious activity. False positives include legitimate capacity reports, backup/troubleshooting scripts, or support operations that enumerate vmdk files without subsequent destructive activity. Remediation emphasizes isolating the host if the same session progresses to VM kills or snapshot deletions, and documenting the user and command for broader hunting across ESXi environments.
Categories
  • Infrastructure
Data Sources
  • Command
  • File
ATT&CK Techniques
  • T1083
Created: 2026-09-30