ESXi Vim-Cmd Enable SSH Service

Rule Info

Name
ESXi Vim-Cmd Enable SSH Service
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of vim-cmd command to enable SSH service on an ESXi hosts. SSH service enables adversaries to laterally move to ESXi hosts and use as an alternative command execution interface.
Date
2025-05-22 00:00:00
Modified
None
Id
6d27f5c9-8c5b-4e3f-9f2a-d9a8f0e5d3b4
Tags
attack.lateral-movement attack.t1021.004 attack.execution attack.t1675
Type
Nextron Sigma feed only (private)

Rule History