%GoCortexIO Snippets

Cortex XDR

Detect early-stage hypervisor attacks for telltale ESXi-specific commands and SSH arguments used by adversaries to prepare lateral movement into your virtualisation estate.

| 5 minutes to implement | ~1 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet - ESXi-targeted command strings on a Windows host.

## Scenario

A Windows beachhead is used to drive administrative tooling against a VMware ESXi estate before the operator pivots onto the hypervisors themselves. ESXi-specific command strings appearing in process command lines on Windows endpoints are an early warning.


Logic: looks for ESXi-only tooling or path fragments in command lines on
Windows hosts. SSH clients (`plink.exe`, `ssh.exe`) carrying these strings
as arguments are particularly worth pivoting on.

- [https://attack.mitre.org/techniques/T1486/](https://attack.mitre.org/techniques/T1486/)
- [https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-039a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-039a)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter agent_os_type = ENUM.AGENT_OS_WINDOWS
| filter lowercase(action_process_image_command_line) contains "esxcli"
    or lowercase(action_process_image_command_line) contains "vim-cmd"
    or lowercase(action_process_image_command_line) contains "vmkfstools"
    or lowercase(action_process_image_command_line) contains "/vmfs/volumes/"
| fields _time, agent_hostname, actor_effective_username,
    causality_actor_process_image_name, action_process_image_command_line
| limit 200
See all 21 snippets