Rule Info
Name
HackTool - Vmkatz Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects patterns indicative of Vmkatz extracting credentials natively from virtual machine snapshots, virtual disks, or NTDS databases directly on hypervisors like ESXi or Proxmox.
Reference
Date
2026-03-25 00:00:00
Modified
None
Id
58718ba9-22ec-45c1-a364-77f199935688
Tags
attack.credential-access attack.t1003.001 attack.t1003.002 attack.t1003.003
Type
Nextron Sigma feed only (private)
