
Rule Info
Name
VMware ESXi Process Termination via Pkill
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to forcefully terminate VMware ESXi virtual machine processes using pkill command.
It is commonly exploited by adversaries to abruptly stop running Virtual Machine (VM) executable processes.
Date
2025-05-20 00:00:00
Modified
None
Id
d357b3d6-93c6-4c71-8f5c-3d2f5401e0f2
Tags
attack.execution attack.t1059.012 attack.impact attack.t1489
Type
Nextron Sigma feed only (private)