Suspicious VMware VM Operations on Sensitive Infrastructure Outside Maintenance Window
This rule monitors for administrative VMware operations (cloning, snapshotting, or process manipulation) performed on sensitive infrastructure servers (such as Domain Controllers, PKI, Vault, or ADFS) that occur outside of a designated maintenance window by non-authorized accounts. It leverages tools like vim-cmd, esxcli, or govc to detect potential unauthorized VM manipulation that could lead to data theft, snapshot-based credential extraction, or unauthorized system changes.
Microsoft Sentinel (KQL)

