VMware
Telemetry Evidence
These values show how indexed rules identify VMware telemetry.Kusto
Syslog VMware_CWS_DLPLogs_CL VMware_CWS_Weblogs_CL VMware_SDWAN_FirewallLogs_CL VMware_VECO_EventLogs_CL VMwareESXi SyslogMessage contains VCF Alert SyslogMessage contains VCF Drop VMware SD-WAN and SASE Splunk
VMWare ESXi Syslog
Detection Rules
Kusto #
- VMware Cloud Web Security - Data Loss Prevention Violation source medium: This Analytics rule receives VMware CWS DLP alerts and combines them with their respective Web Log events. Each Data Loss Prevention event is an alert of policy violations and should be investigated.
- VMware Cloud Web Security - Policy Change Detected source informational: This Analytics rule provides notifications when a VMware CWS policy has been modified. These alerts serve audit purposes. Policy changes might lower the level of security controls.
- VMware Cloud Web Security - Policy Publish Event source informational: This alert is capturing events when VMware CWS policies were published. During publish, the VMware Edge Cloud Orchestrator deploys the CWS policies in SASE POPs, making them effective. All new rules will be enforced. Depending on the contents of the policy, this might create an impact on the CWS Data Plane traffic.
- VMware Cloud Web Security - Web Access Policy Violation source medium: VMware Cloud Web Security reported access events which were violating web access policy rules. Additional investigation might be required.
- VMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected source informational: This analytics rule creates notifications of newly connected devices. These clients are connected to the LAN interface of the Edge.
- VMware ESXi - Dormant VM started source medium: 'Detects when dormant VM was started.'
T1190 - VMware ESXi - Low patch disk space source medium: 'This rule is triggered when low patch disk store space is detected.'
T1529 - VMware ESXi - Low temp directory space source medium: 'This rule is triggered when temp directory space is detected.'
T1529 - VMware ESXi - Multiple Failed Shell Login via SSH source medium: Identifies a failed ESXi Shell login via SSH in a short TimeFrame. This could be suspicious activity especially if this alert is seen triggering many times within a short time frame which could be evidence of a brute-force attack. TriggerThreshold can be adapted.
T1110 - VMware ESXi - Multiple new VMs started source medium: 'Detects when multiple new VMs were started.'
T1078
Show 15 more
- VMware ESXi - Multiple VMs stopped source medium: 'Detects when multiple VMs ware stopped by user.'
T1529 - VMware ESXi - New VM started source medium: 'Detects when new VM was started.'
T1078 - VMware ESXi - Root impersonation source medium: 'Detects when root impersonation occurs.'
T1078 - VMware ESXi - Root login source high: 'Detects when root user login from uncommon IP address.'
T1078 - VMware ESXi - Root password changed source high: 'Detects when root user password is changed.'
T1078,T1098,T1556 - VMware ESXi - Shared or stolen root account source high: 'Detects when shared or stolen root account.'
T1078 - VMware ESXi - SSH Enable on ESXi Host source high: 'Detects when vim-cmd is used to enable SSH on an ESXi host'
T1021 - VMware ESXi - Unexpected disk image source medium: 'Detects unexpected disk image for VM.'
T1496 - VMware ESXi - VM stopped source medium: 'Detects when VM was stopped.'
T1529 - VMware SD-WAN - Orchestrator Audit Event source informational: This rule is searching for configuration changes. Configuration changes can override security measures and the overarching security design. Therefore audit events must be accurately tracked.
- VMware SD-WAN Edge - All Cloud Security Service Tunnels DOWN source medium: This analytics rule collects events where an SD-WAN Edge reports that all Cloud Security Service (CSS) tunnels are down. Losing connectivity to a Secure Service Edge (SSE) service can impact security capabilities.
- VMware SD-WAN Edge - Device Congestion Alert - Packet Drops source medium: The VMware Edge Cloud Orchestrator reported an edge congestion event, where the Edge is dropping a large number of packets on one of its interfaces. This could indicate an ongoing Denial of Service attack against an appliance. Please make sure that Network Flood Protection is turned on.
T1498 - VMware SD-WAN Edge - IDS/IPS Alert triggered (Search API) source high: The VMware SD-WAN Edge appliance captured a potentially malicious traffic flow. Please investigate the IOC information available. This analytics rule analyses Search API streams. Search API queries report only IDS/IPS Alerts. In case you would also need Network Flood Protection, please enable Syslog collection using AMA.
T1210 - VMware SD-WAN Edge - IDS/IPS Signature Update Failed source high: The VMware SD-WAN Edge Management Plane reported a failed IDS/IPS signature update. This can indicate a potential management plane issue, an Edge OS version mismatch (IDS/IPS has been introduced in release 5.2.0.0), or a software issue. If the Edge was able to download signature files before, this error means that the IPS/IDS engine can still provide a level of protection, however, signatures might be missing or inaccurate. If the Edge has no valid signature file, this error could indicate that the Edge Firewall cannot protect from network threats.
- VMware SD-WAN Edge - IDS/IPS Signature Update Succeeded source informational: The VMware SD-WAN Edge Management Plane reported a successful IDS/IPS signature update. New signatures might impact Data Plane traffic, therefore an audit event is generated.
Splunk #
- ESXi Account Modified source low: This detection identifies the creation, deletion, or modification of a local user account on an ESXi host. This activity may indicate unauthorized access, indicator removal, or persistence attempts by an attacker seeking to establish or maintain control of the host.
T1078,T1098,T1136,T1136.001 - ESXi Audit Tampering source medium: This detection identifies the use of the esxcli system auditrecords commands, which can be used to tamper with logging on an ESXi host. This action may indicate an attempt to evade detection or hinder forensic analysis by preventing the recording of system-level audit events.
T1070,T1690 - ESXi Bulk VM Termination source medium: This detection identifies when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.
T1499,T1529,T1673 - ESXi Download Errors source low: This detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in the system logs. These failures may indicate unauthorized or malicious attempts to install or update components—such as VIBs or scripts
T1601,T1601.001,T1685 - ESXi Encryption Settings Modified source medium: Detects the disabling of critical encryption enforcement settings on an ESXi host, such as secure boot or executable verification requirements, which may indicate an attempt to weaken hypervisor integrity or allow unauthorized code execution.
T1685 - ESXi External Root Login Activity source low: This detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user. Direct root access to the UI bypasses role-based access controls and auditing practices, and may indicate risky behavior, misconfiguration, or unauthorized activity by a malicious actor using compromised credentials.
T1078 - ESXi Firewall Disabled source medium: This detection identifies when the ESXi firewall is disabled or set to permissive mode, which can expose the host to unauthorized access and network-based attacks. Such changes are often a precursor to lateral movement, data exfiltration, or the installation of malicious software by a threat actor.
T1686 - ESXi Lockdown Mode Disabled source medium: This detection identifies when Lockdown Mode is disabled on an ESXi host, which can indicate that a threat actor is attempting to weaken host security controls. Disabling Lockdown Mode allows broader remote access via SSH or the host client and may precede further malicious actions such as data exfiltration, lateral movement, or VM tampering.
T1685 - ESXi Loghost Config Tampering source medium: This detection identifies changes to the syslog loghost configuration on an ESXi host, which may indicate an attempt to disrupt log forwarding and evade detection.
T1685 - ESXi Malicious VIB Forced Install source medium: Detects potentially malicious installation of VMware Installation Bundles (VIBs) using the --force flag. The --force option bypasses signature and compatibility checks, allowing unsigned, community-supported, or incompatible VIBs to be installed on an ESXi host. This behavior is uncommon in normal administrative operations and is often observed in post-compromise scenarios where adversaries attempt to install backdoored or unauthorized kernel modules, drivers, or monitoring tools to establish persistence or gain deeper control of the hypervisor.
T1505,T1505.006
Show 13 more
- ESXi Reverse Shell Patterns source medium: This detection looks for reverse shell string patterns on an ESXi host, which may indicate that a threat actor is attempting to establish remote control over the system.
T1059 - ESXi Sensitive Files Accessed source medium: This detection identifies access to sensitive system and configuration files on an ESXi host, including authentication data, service configurations, and VMware-specific management settings. Interaction with these files may indicate adversary reconnaissance, credential harvesting, or preparation for privilege escalation, lateral movement, or persistence.
T1003,T1003.008,T1005 - ESXi Shared or Stolen Root Account source low: This detection monitors for signs of a shared or potentially compromised root account on ESXi hosts by tracking the number of unique IP addresses logging in as root within a short time window. Multiple logins from different IPs in a brief period may indicate credential misuse, lateral movement, or account compromise.
T1078 - ESXi Shell Access Enabled source medium: This detection identifies when the ESXi Shell is enabled on a host, which may indicate that a malicious actor is preparing to execute commands locally or establish persistent access. Enabling the shell outside of approved maintenance windows can be a sign of compromise or unauthorized administrative activity.
T1021 - ESXi SSH Brute Force source low: This detection identifies signs of SSH brute-force attacks by monitoring for a high number of failed login attempts within a short time frame. Such activity may indicate an attacker attempting to gain unauthorized access through password guessing.
T1110 - ESXi SSH Enabled source medium: This detection identifies SSH being enabled on ESXi hosts, which can be an early indicator of malicious activity. Threat actors often use SSH to gain persistent remote access after compromising credentials or exploiting vulnerabilities.
T1021,T1021.004 - ESXi Syslog Config Change source medium: This detection identifies changes to the syslog configuration on an ESXi host using esxcli, which may indicate an attempt to disrupt log collection and evade detection.
T1690 - ESXi System Clock Manipulation source medium: This detection identifies a significant change to the system clock on an ESXi host, which may indicate an attempt to manipulate timestamps and evade detection or forensic analysis
T1070,T1070.006 - ESXi System Information Discovery source medium: This detection identifies the use of ESXCLI system-level commands that retrieve configuration details. While used for legitimate administration, this behavior may also indicate adversary reconnaissance aimed at profiling the ESXi host's capabilities, build information, or system role in preparation for further compromise.
T1082 - ESXi User Granted Admin Role source medium: This detection identifies when a user is granted the Administrator role on an ESXi host. Assigning elevated privileges is a critical action that can indicate potential malicious behavior if performed unexpectedly. Adversaries who gain access may use this to escalate privileges, maintain persistence, or disable security controls.
T1078,T1098 - ESXi VIB Acceptance Level Tampering source medium: This detection identifies changes to the VIB (vSphere Installation Bundle) acceptance level on an ESXi host. Modifying the acceptance level, such as setting it to CommunitySupported, lowers the system's integrity enforcement and may allow the installation of unsigned or unverified software.
T1685 - ESXi VM Discovery source medium: This detection identifies the use of ESXCLI commands to discover virtual machines on an ESXi host While used by administrators, this activity may also indicate adversary reconnaissance aimed at identifying high value targets, mapping the virtual environment, or preparing for data theft or destructive operations.
T1673 - ESXi VM Exported via Remote Tool source medium: This detection identifies the use of a remote tool to download virtual machine disk files from a datastore. The NFC protocol is used by management tools to transfer files to and from ESXi hosts, but it can also be abused by attackers or insiders to exfiltrate full virtual disk images
T1005
Product-Filtered Rules
These rules use generic transport telemetry with a product-specific filter for VMware.Kusto #
T1210T1498, T1599T1498