Unauthorized VM Cloning of Sensitive Systems in VMware vCenter/ESXi
Detects attempts to clone or snapshot sensitive virtual machines (such as Domain Controllers, PKI, Vault, ADFS, or SSO servers) in a VMware environment. The rule alerts on these activities when performed by non-administrator accounts outside of established maintenance windows, suggesting potential unauthorized data staging or credential extraction.
Microsoft Sentinel (KQL)

