Skip to content

Hide Navigation Hide TOC

ESXi VSAN Information Discovery Via ESXCLI (d54c2f06-aca9-4e2b-81c9-5317858f4b79)

Detects execution of the "esxcli" command with the "vsan" flag in order to retrieve information about virtual storage. Seen used by malware such as DarkSide.

Cluster A Galaxy A Cluster B Galaxy B Level
System Owner/User Discovery - T1033 (03d7999c-1f4c-42cc-8373-e7690d318104) Attack Pattern ESXi VSAN Information Discovery Via ESXCLI (d54c2f06-aca9-4e2b-81c9-5317858f4b79) Sigma-Rules 1
ESXi VSAN Information Discovery Via ESXCLI (d54c2f06-aca9-4e2b-81c9-5317858f4b79) Sigma-Rules System Service Discovery - T1007 (322bad5a-1c49-4d23-ab79-76d641794afa) Attack Pattern 1