heroui logo

ESXi Virtual Machine Powered Off

Elastic Detection Rules

View Source
Summary
Detects ESXi host activity where vim-cmd vmsvc/power.off is invoked, indicating a shutdown of one or more virtual machines. This power-off action releases the hypervisor’s lock on virtual disks, potentially enabling disk rewriting or encryption while the guest is down. The rule targets logs from the vSphere data stream (vsphere.log) and flags occurrences of the vmsvc/power.off command. It is capable of catching both single-VM shutdowns and loops that power off all VMs (e.g., via getallvms), a pattern often observed in ransomware operations. The rule includes triage guidance for differentiating legitimate maintenance from malicious activity, false-positive considerations, and recommended response steps. It also notes prerequisite setup (Elastic vSphere integration) and links to investigative references. The rule’s risk score is 47 with a medium severity, and it uses a KQL query against the vsphere.log data stream to detect the event.
Categories
  • Infrastructure
Data Sources
  • Application Log
ATT&CK Techniques
  • T1529
Created: 2026-09-30