vSphere and BRICKSTORM Malware: A Defender's Guide
ID: 63add8a3-0918-5912-a69b-7872684b45c3
STIX ID: report--63add8a3-0918-5912-a69b-7872684b45c3
Feed Name: Google Cloud Threat Intelligence
This report assesses risks tied to the vCenter Server Appliance (VCSA), explaining how compromise of the VCSA can provide centralized control over ESXi hosts and VMs, enable total data access, and hinder recovery (especially when AD-integrated or when running end-of-life vSphere). It highlights management-plane dependencies, vSphere 7 EoL risks, and prescribes a four-phase defensive strategy—benchmarking and base controls, identity management, vSphere network hardening, and logging/forensic visibility—focusing on Photon OS and hypervisor hardening and behavioral detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
