vmwarehigh
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
CrowdStrike researchers have identified 21 novel methods for obfuscating shell commands on VMware ESX hypervisors. These techniques, ranging from simple encoding to complex cryptographic ciphers and invisible Unicode characters, evade traditional log-based detection by exploiting the parsing stage of command execution. CrowdStrike has developed detection patterns to identify these obfuscated commands at scale, enhancing security for ESX environments frequently targeted by ransomware.