HackTool - Vmkatz Execution - Linux

Rule Info

Name
HackTool - Vmkatz Execution - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects patterns indicative of Vmkatz extracting credentials natively from virtual machine snapshots, virtual disks, or NTDS databases directly on hypervisors like ESXi or Proxmox.
Date
2026-03-25 00:00:00
Modified
None
Id
c5707e0e-b8ac-4010-892d-22b3518121ee
Tags
attack.credential-access attack.t1003.001 attack.t1003.002 attack.t1003.003
Type
Nextron Sigma feed only (private)

Rule History