ESXi Virtual Machine Snapshot Removed

Detects removal of all snapshots for an ESXi virtual machine. Snapshots are on-host recovery points for a guest. Removing all of them deletes those recovery points, so the virtual machine cannot be reverted to an earlier disk state.

Rule type: query
Rule indices:

  • logs-vsphere.log-*

Rule Severity: high
Risk Score: 73
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:

Tags:

  • Domain: Endpoint
  • Data Source: VMware vSphere
  • Use Case: Threat Detection
  • Tactic: Impact
  • Resources: Investigation Guide
  • Rule Type: Custom Query (KQL)
  • Platform: VMware ESXi
  • Threat: Ransomware

Version: 1
Rule authors:

  • Elastic

Rule license: Elastic License v2

This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere

Snapshots are the local recovery point on a datastore. snapshot.removeall deletes them for one VM id. Ransomware wraps that command in a loop over every VM.

  • Read the VM id in message. A loop that calls removeall for every id from getallvms is higher severity than one VM.
  • Check whether VM processes were killed or disks were enumerated in the same session.
  • Ask the backup or virtualization owner whether snapshot consolidation was underway.

Backup products and administrators delete snapshots after a successful consolidate. Match the account and the change ticket before closing the alert.

  • If removal was not approved, isolate the host and stop the shell session.
  • Restore affected VMs from an off-host backup. Datastore snapshots removed by this command are gone.
  • Preserve shell history and hostd logs.
data_stream.dataset: "vsphere.log" and (
  message: "snapshot.removeall"
)
		

Framework: MITRE ATT&CK