ESXi VSAN Information Discovery Via ESXCLI

 Original Source: [Sigma source]
Title: ESXi VSAN Information Discovery Via ESXCLI
Status: test
Description:Detects execution of the "esxcli" command with the "vsan" flag in order to retrieve information about virtual storage. Seen used by malware such as DarkSide.
References:
  -https://www.trendmicro.com/en_us/research/21/e/darkside-linux-vms-targeted.html
  -https://www.trendmicro.com/en_us/research/22/a/analysis-and-Impact-of-lockbit-ransomwares-first-linux-and-vmware-esxi-variant.html
  -https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_vsan.html
Author: Nasreddine Bencherchali (Nextron Systems), Cedric Maurugeon
Date: 2023-09-04
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.execution'
  • -'attack.t1033'
  • -'attack.t1007'
  • -'attack.t1059.012'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection_img:
    Image|endswith: '/esxcli'
    CommandLine|contains: 'vsan'
  selection_cli:
    CommandLine|contains:
      -' get'
      -' list'

  condition:all of selection_*
Falsepositives:
  -Legitimate administration activities
Level: medium