Sub-technique of T1059 Command and Scripting Interpreter.View on attack.mitre.org
Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts.
For example, on ESXi systems, tools such as `esxcli` and `vim-cmd` allow administrators to configure firewall rules and log forwarding on the hypervisor, list virtual machines, start and stop virtual machines, and more. Adversaries may be able to leverage these tools in order to support further actions, such as File and Directory Discovery or Data Encrypted for Impact.
Rules on DetectionCode tagged with T1059.012.
| Rule | Level | Log source |
|---|---|---|
| ESXi Admin Permission Assigned To Account Via ESXCLI | high | linux / process_creation |
| ESXi Account Creation Via ESXCLI | medium | linux / process_creation |
| ESXi Network Configuration Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi Storage Information Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi Syslog Configuration Change Via ESXCLI | medium | linux / process_creation |
| ESXi System Information Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi VM Kill Via ESXCLI | medium | linux / process_creation |
| ESXi VM List Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi VSAN Information Discovery Via ESXCLI | medium | linux / process_creation |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| Used by | Procedure example |
|---|---|
| MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli` in order to terminate running virtual machines. |
| MalwareRoyal | Royal ransomware uses `esxcli` to gather a list of running VMs and terminate them. |
| MalwareVIRTUALPIE | VIRTUALPIE is capable of command line execution on compromised ESXi servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.