CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
ID: 6cf638ce-65a5-5e30-a351-1d1c79e4d217
STIX ID: report--6cf638ce-65a5-5e30-a351-1d1c79e4d217
Feed Name: Crowdstrike Blog
This CrowdStrike research details 21 distinct command-obfuscation techniques that work in the BusyBox-based ESX shell — ranging from escape-sequence encoding and character-generation to invisible Unicode injection, cryptographic encodings, infrastructure-keyed payloads, VMFS steganography, and alternative encodings (Morse, binary, scientific notation). The report demonstrates how these techniques let adversaries evade keyword-based logging and detection, documents validation on ESX 7.0.3, maps the techniques to MITRE ATT&CK, and supplies regex-based CrowdStrike Query Language detection patterns and a correlation rule template for Falcon Next-Gen SIEM to hunt and detect obfuscated ESX shell commands at scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
