heroui logo

ESXi Virtual Machine Snapshot Removed

Elastic Detection Rules

View Source
Summary
Technical summary: Detects the removal of all VM snapshots on an ESXi host by monitoring the vSphere logs for the snapshot.removeall operation. Deleting every snapshot erases on-host recovery points, preventing rollback to a previous disk state. The rule targets the vsphere.log dataset and matches messages containing snapshot.removeall, aligning with MITRE ATT&CK technique T1490 (Inhibit System Recovery) under the Impact tactic. While high-severity, false positives can occur during legitimate maintenance or backup consolidation that consolidates or deletes snapshots; verify whether the operation affected a single VM or all VMs and confirm the initiating account's authorization. Investigative focus should include extracting the VM ID, examining session activity, and checking for concurrent disk enumeration or process termination, as well as corroborating with backups or change tickets. Recommended response includes isolating the host if unauthorized, terminating the session, and restoring affected VMs from off-host backups. Preserve shell history and hostd logs for forensics. Setup requires the Elastic vSphere integration to ingest ESXi logs. References to VMware security and related analyses are provided within the rule metadata for context.
Categories
  • Infrastructure
Data Sources
  • Snapshot
ATT&CK Techniques
  • T1490
Created: 2026-09-30