
Summary
Detects an ESXi host process launched from the ESXi shell that targets datastore paths under /vmfs/volumes. The datastore holds virtual disks for all guests, so a process reading or encrypting these disks could take hosted VMs offline. The rule relies on ESXi host logs collected via the Elastic vSphere integration and flags activity where the log message references both /vmfs/volumes and a suspicious invocation path such as /tmp/ or a Python command. MITRE mapping ties this activity to Execution (T1059, Unix Shell T1059.004) and to Impact (T1486: Data Encrypted for Impact), indicating a potential ransomware-like operation that could read or encrypt guest disks. The rule includes a high risk score (73) and high severity, signaling critical attention. It also provides a structured triage and investigation guide, false positive considerations (e.g., approved maintenance scripts or inventory checks in /tmp), and remediation steps (isolate host, remove /tmp artifacts, and restore modified datastores from backups).
Categories
- Endpoint
Data Sources
- Process
ATT&CK Techniques
- T1059
- T1059.004
- T1486
Created: 2026-09-30