heroui logo

ESXi Virtual Machine Process Killed

Elastic Detection Rules

View Source
Summary
Detects termination of a virtual machine process on an ESXi host, including esxcli vm process kill, pkill of vmx processes, and vmdumper suspend. When a VM is running, it holds a lock on its disks; stopping the process releases the lock and makes the disks writable, which is a tactic observed in ESXi ransomware operations prior to encryption. The rule queries ESXi host logs collected via the Elastic vSphere integration, looking for log entries that indicate a VM process kill or related commands. The matching criteria use data_stream.dataset:vsphere.log with a message pattern that includes "vm process kill" or a combination of pkill with vmx or suspend_v with vmdumper. Investigations should extract the full command, world-id, and account from surrounding logs, verify if similar actions enumerated VMs or disrupted snapshots, and confirm whether the shutdown was authorized. False positives occur during maintenance, host upgrades, or troubleshooting, where a soft/controlled kill may occur within a change window. Recommended response includes isolating the host from the management network if unauthorized, preserving relevant logs (shell.log, hostd.log, auth.log), and restoring any affected VM from known-good backups. The rule is designed to help identify ransomware-like activity that begins by breaking disk locks to facilitate encryption, and should be correlated with other IOC/SOC data for confirmation.
Categories
  • Infrastructure
Data Sources
  • Process
ATT&CK Techniques
  • T1489
Created: 2026-09-30