{"id":"T1673","name":"Virtual Machine Discovery","url":"https://attack.mitre.org/techniques/T1673","tactics":["discovery"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0199","stix_id":"x-mitre-detection-strategy--85849149-b36f-4562-9478-65c4e8f97dec","name":"Detection Strategy for Virtual Machine Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0199","analytics":[{"id":"AN0572","stix_id":"x-mitre-analytic--44bb0cf8-12ee-4a8f-8701-6c787a008bd8","name":"Analytic 0572","description":"Monitor for execution of hypervisor management commands such as `esxcli vm process list` or `vim-cmd vmsvc/getallvms` that enumerate virtual machines. Defenders observe unexpected users issuing VM listing commands outside normal administrative workflows.","url":"https://attack.mitre.org/detectionstrategies/DET0199#AN0572","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"command IN (\"esxcli vm process list\", \"vim-cmd vmsvc/getallvms\")","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"ExpectedAdminUsers","description":"List of known administrators authorized to run ESXi enumeration commands."},{"field":"UnexpectedCommandPaths","description":"Defines restricted paths or contexts where VM enumeration should not occur."}],"live":true,"detection_strategies":["DET0199"],"techniques":["T1673"]},{"id":"AN0573","stix_id":"x-mitre-analytic--753ec5a6-9327-452e-ab9c-62b7206c24aa","name":"Analytic 0573","description":"Detects attempts to enumerate VMs via hypervisor tools like `virsh`, `VBoxManage`, or `qemu-img`. Defender correlates suspicious command invocations with parent process lineage and unexpected users.","url":"https://attack.mitre.org/detectionstrategies/DET0199#AN0573","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: process_name IN (\"virsh\", \"VBoxManage\", \"qemu-img\") AND command IN (\"list\", \"info\")","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"NonRootAccounts","description":"Monitor non-root users invoking hypervisor management utilities."},{"field":"KnownAdminScripts","description":"Whitelist of scripts expected to run VM enumeration as part of routine operations."}],"live":true,"detection_strategies":["DET0199"],"techniques":["T1673"]},{"id":"AN0574","stix_id":"x-mitre-analytic--be2239de-ae8e-442d-a9f6-d34460b94e94","name":"Analytic 0574","description":"Detects enumeration of VMs using PowerShell (`Get-VM`), VMware Workstation (`vmrun.exe`), or Hyper-V (`VBoxManage.exe`). Defender observes suspicious command lines executed by unexpected users or outside normal administrative sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0199#AN0574","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"ExpectedAdminAccounts","description":"Defines which accounts are authorized to execute VM discovery commands."},{"field":"RoutineScripts","description":"Whitelist of approved administrative scripts that legitimately invoke VM enumeration."}],"live":true,"detection_strategies":["DET0199"],"techniques":["T1673"]},{"id":"AN0575","stix_id":"x-mitre-analytic--86bb41b4-5c8a-4407-b788-8f6ea8457860","name":"Analytic 0575","description":"Detects VM enumeration attempts using virtualization utilities such as VirtualBox (`VBoxManage`) or Parallels CLI. Defender observes abnormal invocation of VM listing commands correlated with non-admin users or unusual parent processes.","url":"https://attack.mitre.org/detectionstrategies/DET0199#AN0575","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process_name IN (\"VBoxManage\", \"prlctl\") AND command CONTAINS (\"list\", \"show\")","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UserContext","description":"Adjust sensitivity depending on whether the command is executed by admin or non-admin users."},{"field":"ExecutionTimeWindow","description":"Restrict alerts to unusual times when VM management is not expected."}],"live":true,"detection_strategies":["DET0199"],"techniques":["T1673"]}],"live":true,"version":"1.0","techniques":["T1673"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}