VMware

Telemetry Evidence

These values show how indexed rules identify VMware telemetry.

Kusto

  • Queried source table Syslog (3 rules)
  • Queried source table VMware_CWS_DLPLogs_CL (1 rule)
  • Queried source table VMware_CWS_Weblogs_CL (2 rules)
  • Queried source table VMware_SDWAN_FirewallLogs_CL (1 rule)
  • Queried source table VMware_VECO_EventLogs_CL (8 rules)
  • Queried source table VMwareESXi (14 rules)
  • Query discriminator SyslogMessage contains VCF Alert (1 rule)
  • Query discriminator SyslogMessage contains VCF Drop (2 rules)
  • Source collection VMware SD-WAN and SASE (3 rules)

Splunk

  • Data source VMWare ESXi Syslog (23 rules)

Detection Rules

Kusto #

Show 15 more

Splunk #

  • ESXi Account Modified source low: This detection identifies the creation, deletion, or modification of a local user account on an ESXi host. This activity may indicate unauthorized access, indicator removal, or persistence attempts by an attacker seeking to establish or maintain control of the host.T1078, T1098, T1136, T1136.001
  • ESXi Audit Tampering source medium: This detection identifies the use of the esxcli system auditrecords commands, which can be used to tamper with logging on an ESXi host. This action may indicate an attempt to evade detection or hinder forensic analysis by preventing the recording of system-level audit events.T1070, T1690
  • ESXi Bulk VM Termination source medium: This detection identifies when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.T1499, T1529, T1673
  • ESXi Download Errors source low: This detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in the system logs. These failures may indicate unauthorized or malicious attempts to install or update components—such as VIBs or scriptsT1601, T1601.001, T1685
  • ESXi Encryption Settings Modified source medium: Detects the disabling of critical encryption enforcement settings on an ESXi host, such as secure boot or executable verification requirements, which may indicate an attempt to weaken hypervisor integrity or allow unauthorized code execution.T1685
  • ESXi External Root Login Activity source low: This detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user. Direct root access to the UI bypasses role-based access controls and auditing practices, and may indicate risky behavior, misconfiguration, or unauthorized activity by a malicious actor using compromised credentials.T1078
  • ESXi Firewall Disabled source medium: This detection identifies when the ESXi firewall is disabled or set to permissive mode, which can expose the host to unauthorized access and network-based attacks. Such changes are often a precursor to lateral movement, data exfiltration, or the installation of malicious software by a threat actor.T1686
  • ESXi Lockdown Mode Disabled source medium: This detection identifies when Lockdown Mode is disabled on an ESXi host, which can indicate that a threat actor is attempting to weaken host security controls. Disabling Lockdown Mode allows broader remote access via SSH or the host client and may precede further malicious actions such as data exfiltration, lateral movement, or VM tampering.T1685
  • ESXi Loghost Config Tampering source medium: This detection identifies changes to the syslog loghost configuration on an ESXi host, which may indicate an attempt to disrupt log forwarding and evade detection.T1685
  • ESXi Malicious VIB Forced Install source medium: Detects potentially malicious installation of VMware Installation Bundles (VIBs) using the --force flag. The --force option bypasses signature and compatibility checks, allowing unsigned, community-supported, or incompatible VIBs to be installed on an ESXi host. This behavior is uncommon in normal administrative operations and is often observed in post-compromise scenarios where adversaries attempt to install backdoored or unauthorized kernel modules, drivers, or monitoring tools to establish persistence or gain deeper control of the hypervisor.T1505, T1505.006
Show 13 more
  • ESXi Reverse Shell Patterns source medium: This detection looks for reverse shell string patterns on an ESXi host, which may indicate that a threat actor is attempting to establish remote control over the system.T1059
  • ESXi Sensitive Files Accessed source medium: This detection identifies access to sensitive system and configuration files on an ESXi host, including authentication data, service configurations, and VMware-specific management settings. Interaction with these files may indicate adversary reconnaissance, credential harvesting, or preparation for privilege escalation, lateral movement, or persistence.T1003, T1003.008, T1005
  • ESXi Shared or Stolen Root Account source low: This detection monitors for signs of a shared or potentially compromised root account on ESXi hosts by tracking the number of unique IP addresses logging in as root within a short time window. Multiple logins from different IPs in a brief period may indicate credential misuse, lateral movement, or account compromise.T1078
  • ESXi Shell Access Enabled source medium: This detection identifies when the ESXi Shell is enabled on a host, which may indicate that a malicious actor is preparing to execute commands locally or establish persistent access. Enabling the shell outside of approved maintenance windows can be a sign of compromise or unauthorized administrative activity.T1021
  • ESXi SSH Brute Force source low: This detection identifies signs of SSH brute-force attacks by monitoring for a high number of failed login attempts within a short time frame. Such activity may indicate an attacker attempting to gain unauthorized access through password guessing.T1110
  • ESXi SSH Enabled source medium: This detection identifies SSH being enabled on ESXi hosts, which can be an early indicator of malicious activity. Threat actors often use SSH to gain persistent remote access after compromising credentials or exploiting vulnerabilities.T1021, T1021.004
  • ESXi Syslog Config Change source medium: This detection identifies changes to the syslog configuration on an ESXi host using esxcli, which may indicate an attempt to disrupt log collection and evade detection.T1690
  • ESXi System Clock Manipulation source medium: This detection identifies a significant change to the system clock on an ESXi host, which may indicate an attempt to manipulate timestamps and evade detection or forensic analysisT1070, T1070.006
  • ESXi System Information Discovery source medium: This detection identifies the use of ESXCLI system-level commands that retrieve configuration details. While used for legitimate administration, this behavior may also indicate adversary reconnaissance aimed at profiling the ESXi host's capabilities, build information, or system role in preparation for further compromise.T1082
  • ESXi User Granted Admin Role source medium: This detection identifies when a user is granted the Administrator role on an ESXi host. Assigning elevated privileges is a critical action that can indicate potential malicious behavior if performed unexpectedly. Adversaries who gain access may use this to escalate privileges, maintain persistence, or disable security controls.T1078, T1098
  • ESXi VIB Acceptance Level Tampering source medium: This detection identifies changes to the VIB (vSphere Installation Bundle) acceptance level on an ESXi host. Modifying the acceptance level, such as setting it to CommunitySupported, lowers the system's integrity enforcement and may allow the installation of unsigned or unverified software.T1685
  • ESXi VM Discovery source medium: This detection identifies the use of ESXCLI commands to discover virtual machines on an ESXi host While used by administrators, this activity may also indicate adversary reconnaissance aimed at identifying high value targets, mapping the virtual environment, or preparing for data theft or destructive operations.T1673
  • ESXi VM Exported via Remote Tool source medium: This detection identifies the use of a remote tool to download virtual machine disk files from a datastore. The NFC protocol is used by management tools to transfer files to and from ESXi hosts, but it can also be abused by attackers or insiders to exfiltrate full virtual disk imagesT1005

Product-Filtered Rules

These rules use generic transport telemetry with a product-specific filter for VMware.

Kusto #

  • VMware SD-WAN Edge - IDS/IPS Alert triggered (Syslog) source high: The VMware SD-WAN Edge appliance captured a potentially malicious traffic flow. Please investigate the IOC information available. This analytics rule analyzes Syslog streams.T1210
  • VMware SD-WAN Edge - Network Anomaly Detection - Potential Fragmentation Attack source low: The VMware SD-WAN Edge appliance received packets potentially part of an IP Fragmentation attack or indicating an MTU mismatch. An IP fragmentation attack is a cyberattack that exploits how IP packets are fragmented and reassembled. IP fragmentation is a process by which large IP packets are broken down into smaller packets to transmit them over networks with smaller Maximum Transmission Unit (MTU) sizes. Attackers can exploit IP fragmentation in various ways, for example, Denial-of-service attacks, address spoofing, or even information disclosure. This analytics rule analyzes Syslog streams; these alerts are not reported by default if Search API is used.T1498, T1599
  • VMware SD-WAN Edge - Network Anomaly Detection - RPF Check Failure source low: The VMware SD-WAN Edge appliance received packets that failed a Reverse Path Forwarding (RPF) Check. Reverse path forwarding (RPF) check is a network security mechanism that verifies whether the source IP address of a packet is reachable through the incoming interface on which the packet is received. The packet is dropped if the source IP address is not reachable through the incoming interface. RPF checks prevent spoofing attacks, in which an attacker uses a forged source IP address to make it appear that the packets are coming from a trusted source. This can allow the attacker to gain unauthorized network access or launch a denial-of-service attack against a target system. An IP fragmentation attack is a cyberattack that exploits how IP packets are fragmented and reassembled. IP fragmentation is a process by which large IP packets are broken down into smaller packets to transmit them over networks with smaller Maximum Transmission Unit (MTU) sizes. This analytics rule analyzes Syslog streams; these alerts are not reported by default if Search API is used.T1498