Virtualization Management Plane Tampering via ESXi/Hyper-V Tools
Detects unauthorized or suspicious use of virtualization management tools (e.g., esxcli, vim-cmd, PowerShell cmdlets for vSphere/Hyper-V) to perform disruptive actions such as powering off VMs, removing snapshots, or modifying firewall configurations. The rule excludes activity originating from standard management processes and trusted VMware/Microsoft signed processes.
SentinelOne

