ATT&CK · T1059.012 · sub-technique
Hypervisor CLI
Tactics: execution
About
Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself and the guest virtual machines it hosts. For example, on ESXi systems, tools such as `esxcli` and `vim-cmd` allow administrators to configure firewall rules and log forwarding on the hypervisor, list virtual machines, start and stop virtual machines, and more. Adversaries may be able to leverage these tools in order to support further actions, such as File and Directory Discovery or Data Encrypted for Impact.
Used by actors
1 known groups
Software
3 malware/tools implement this
Corpus indicators tagged with this technique
0 indicators in the corpus carry T1059.012.
No corpus indicators are tagged with this technique yet.