Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-18 | ✗→✓ | ▲ Improved | -23% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 36% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -78% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -25% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -2% | 0% |
Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment. Persistent background services on ESXi-hosted VMs, such as the VMware Tools Daemon Service, allow for remote management from the ESXi server. The tools daemon service runs as vmtoolsd.exe on Windows guest operating systems, vmware-tools-daemon on macOS, and vmtoolsd on Linux.
Adversaries may leverage a variety of tools to execute commands on ESXi-hosted VMs – for example, by using the vSphere Web Services SDK to programmatically execute commands and scripts via APIs such as StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, and InitiateFileTransferFromGuest. This may enable follow-on behaviors on the guest VMs, such as File and Directory Discovery, Data from Local System, or OS Credential Dumping.
Platforms: ESXi
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
If not required, restrict the permissions of users to perform Guest Operations on ESXi-hosted VMs.
| Finding | Severity | Impact | | ------------------------------------------------ | -------- | --------- | | ESXi Administration Command technique applicable | High | Execution |
| CWE ID | Title | | ------ | -------------------------------------- | | CWE-94 | Improper Control of Generation of Code |
Other measured skills in the registry, with their headline benchmark lift.