Command and Scripting Interpreter: Hypervisor CLI T1059.012
Tactic: Execution
Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 9 rules share fields, values, and exclusions.
Fields filtered most (2 distinct)
These fields appear most often in rule filters.
Top indicator values (18 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint
Sigma 9 rules
- ESXi Account Creation Via ESXCLI
- ESXi Admin Permission Assigned To Account Via ESXCLI
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi Syslog Configuration Change Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi VM Kill Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI