ESXi Syslog Config Change — Detection Rule

This detection identifies changes to the syslog configuration on an ESXi host using esxcli, which may indicate an attempt to disrupt log collection and evade detection.

Read the full analysis on IntelFusions