ESXi/vCenter Management Plane Destruction Activity
Detects high-risk administrative activity on VMware ESXi or vCenter servers that is consistent with pre-ransomware staging, such as disabling lockdown mode, disabling syslog forwarding, mass deletion or modification of virtual machine files (.vmdk/.vmx), or shell command execution related to encryption tool staging.
Microsoft Sentinel (KQL)

