
Rule Info
Name
ESXi Firewall Disabled via ESXCLI
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects potential malicious activity where attackers use ESXCLI command to disable ESXi host firewall.
Threat Actors may use this technique to remove network security restrictions and facilitate their malicious operations.
Date
2025-05-19 00:00:00
Modified
None
Id
2c195f09-6a11-4155-be2c-47d357c62805
Tags
attack.execution attack.t1675 attack.defense-evasion attack.t1562.004
Type
Nextron Sigma feed only (private)