T1673 Virtual Machine Discovery
An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a [Hypervisor CLI](https://attack.mitre.org/techniques/T1059/012) such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`).(Citation: Crowdstrike Hypervisor Jackpotting…
Who uses it · with stories on Jábega
Sigma rules to hunt it
SigmaHQ has no rules for this technique.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.