logo

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

ID: 6cf638ce-65a5-5e30-a351-1d1c79e4d217

STIX ID: report--6cf638ce-65a5-5e30-a351-1d1c79e4d217

Feed Name: Crowdstrike Blog

Threat Score
75/100

Date Published: 2026-08-07

Date Updated: 2026-08-10

Author: Erez Goldberg

...
...

This CrowdStrike research details 21 distinct command-obfuscation techniques that work in the BusyBox-based ESX shell — ranging from escape-sequence encoding and character-generation to invisible Unicode injection, cryptographic encodings, infrastructure-keyed payloads, VMFS steganography, and alternative encodings (Morse, binary, scientific notation). The report demonstrates how these techniques let adversaries evade keyword-based logging and detection, documents validation on ESX 7.0.3, maps the techniques to MITRE ATT&CK, and supplies regex-based CrowdStrike Query Language detection patterns and a correlation rule template for Falcon Next-Gen SIEM to hunt and detect obfuscated ESX shell commands at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.