
Summary
This rule detects ESXi host activity where curl or wget are invoked from the ESXi shell to download a file or contact a remote URL. The ESXi shell may download a payload to the host (commonly under /tmp), which could be executed later against the datastore. The detection relies on the Elastic vSphere integration and inspects vsphere.log for messages containing curl or wget. The KQL query is data_stream.dataset: "vsphere.log" and event.module: "vsphere" and message: ("curl" or "wget"). A match suggests potential command-and-control or payload transfer activity, consistent with Ingress Tool Transfer (MITRE T1105) and the Command and Control tactic (TA0011). The rule is categorized with medium severity and a risk score of 47, and is intended for production use in VMware ESXi environments.
Categories
- Infrastructure
- Endpoint
Data Sources
- Application Log
- Command
- Process
ATT&CK Techniques
- T1105
Created: 2026-09-30