tag: Shell-Obfuscation · 1 items
- Engineer — Learn: Describes how threat actors obfuscate shell commands on ESXi hosts — no patch action indicated from the title alone, but useful for understanding attacker technique when designing ESXi hardening and logging posture.
- SOC/IR — Plan: CrowdStrike’s hunting methodology for ESXi shell obfuscation is directly adoptable; schedule a review of the techniques and build or adapt hunt queries targeting ESXi command-line anomalies in your SIEM this quarter.
- Leader — Skip