Command and Scripting Interpreter: Hypervisor CLI T1059.012

Tactic: Execution

Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 9 rules share fields, values, and exclusions.

Fields filtered most (2 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine9contains 9, ends_with 1 list, get, set, vm process, permission
Image9ends_with 9/esxcli

Top indicator values (18 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Imageends_with
/esxcli
99
CommandLinecontains
get
44
CommandLinecontains
list
44
CommandLinecontains
system
39
CommandLinecontains
set
22
CommandLinecontains
vm process
22
CommandLinecontains
permission
1
CommandLinecontains
account
1
CommandLinecontains
add
112
CommandLinecontains
admin
14
CommandLinecontains
config
116
CommandLinecontains
kill
1
CommandLinecontains
network
13
CommandLinecontains
storage
12
CommandLinecontains
syslog
1
CommandLinecontains
system
1
CommandLinecontains
vsan
1
CommandLineends_with
list
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Sigma 9 rules