ESXi Virtual Machine Process Killed

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects termination of a virtual machine process on an ESXi host, including `esxcli vm process kill`, `pkill` of `vmx` processes, and `vmdumper` suspend. A running VM holds a lock on its disks. Stopping the process releases that lock and makes the disks writable.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: ImpactRule Type: Custom Query (KQL)Platform: VMware ESXiThreat: RansomwareLanguage: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Impact (TA0040)(external, opens in a new tab or window)

False Positive Examples
Virtual machine process kills also happen during planned maintenance, host upgrades, and troubleshooting of a stuck VM. Confirm the world id, the account, and whether the same session also enumerates `/vmfs/volumes` or removes snapshots.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-vsphere.log-*
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:vsphere.log and message:("vm process kill" or pkill and vmx or suspend_v and vmdumper)

Install detection rules in Elastic Security

Detect ESXi Virtual Machine Process Killed in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).