ESXi Storage Information Discovery Via ESXCLI — Detection Rule

Detects execution of the "esxcli" command with the "storage" flag in order to retrieve information about the storage status and other related information. Seen used by malware such as DarkSide and LockBit.

Read the full analysis on IntelFusions