ESXi/vCenter Management Plane Destruction Activity

Detects high-risk administrative activity on VMware ESXi or vCenter servers that is consistent with pre-ransomware staging, such as disabling lockdown mode, disabling syslog forwarding, mass deletion or modification of virtual machine files (.vmdk/.vmx), or shell command execution related to encryption tool staging.