
Rule Info
Name
ESXi Coredump File Creation Disabled via ESXCLI
Author
Swachchhhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to disable coredump file creation in ESXi systems via ESXCLI, which could indicate defense evasion tactics by adversaries trying to prevent forensic analysis.
Coredump files are crucial for post-incident investigation and system diagnostics, and threat actors uses this technique very often.
Date
2025-05-19 00:00:00
Modified
None
Id
7629ff45-e6f5-4c7a-82c4-6a0603f50d21
Tags
attack.execution attack.t1675 attack.defense-evasion attack.t1562.001
Type
Nextron Sigma feed only (private)