Technique.View on attack.mitre.org
An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a Hypervisor CLI such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`). Adversaries may also directly leverage a graphical user interface, such as VMware vCenter, in order to view virtual machines on a host.
Adversaries may use the information from Virtual Machine Discovery during discovery to shape follow-on behaviors. Subsequently discovered VMs may be leveraged for follow-on activities such as Service Stop or Data Encrypted for Impact.
Rules on DetectionCode tagged with T1673.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ESXi Bulk VM Termination | TTP | NULL | VMWare ESXi Syslog |
| ESXi VM Discovery | TTP | NULL | VMWare ESXi Syslog |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupUNC3886 | UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs. |
| Used by | Procedure example |
|---|---|
| MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them. |
| MalwarePureCrypter | PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual. |
| MalwareQilin | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments. |
| MalwareVIRTUALPITA | VIRTUALPITA can target specific guest virtual machines for script execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.