heroui logo

ESXi Curl or Wget Activity

Elastic Detection Rules

View Source
Summary
This rule detects ESXi host activity where curl or wget are invoked from the ESXi shell to download a file or contact a remote URL. The ESXi shell may download a payload to the host (commonly under /tmp), which could be executed later against the datastore. The detection relies on the Elastic vSphere integration and inspects vsphere.log for messages containing curl or wget. The KQL query is data_stream.dataset: "vsphere.log" and event.module: "vsphere" and message: ("curl" or "wget"). A match suggests potential command-and-control or payload transfer activity, consistent with Ingress Tool Transfer (MITRE T1105) and the Command and Control tactic (TA0011). The rule is categorized with medium severity and a risk score of 47, and is intended for production use in VMware ESXi environments.
Categories
  • Infrastructure
  • Endpoint
Data Sources
  • Application Log
  • Command
  • Process
ATT&CK Techniques
  • T1105
Created: 2026-09-30