CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
crowdstrike.com | blog | #threat-detection | #detection-engineering | #ransomware | #command-obfuscation | #threat-hunting | #vmware-esxi | #crowdstrike | #vmware-esx
Summary
CrowdStrike cataloged 21 command obfuscation methods on VMware ESX's BusyBox shell—ciphers, keyed payloads, alternative encodings—and built CQL detections; ESX logs capture commands pre-expansion.
- Published
- Collected
Skip to content