FORENSIA

ATT&CK · T1673

Virtual Machine Discovery

Tactics: discovery

About

An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a Hypervisor CLI such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`). Adversaries may also directly leverage a graphical user interface, such as VMware vCenter, in order to view virtual machines on a host. Adversaries may use the information from Virtual Machine Discovery during discovery to shape follow-on behaviors. Subsequently discovered VMs may be leveraged for follow-on activities such as Service Stop or Data Encrypted for Impact.

Platforms: ESXi, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

1 known groups

Software

4 malware/tools implement this

CheerscryptVIRTUALPITAQilinPureCrypter

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1673.

No corpus indicators are tagged with this technique yet.