ESXi Curl or Wget Activity
Description
Detects curl or wget from the ESXi shell. These tools download a file or contact a remote URL from the
hypervisor. A successful transfer can place a package or script on the host, often under /tmp, where a later
command can execute it against the datastore.
Query · kuery
data_stream.dataset: "vsphere.log" and event.module: "vsphere" and message: ("curl" or "wget")
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators use `wget` to download a patch, VIB, or support script during maintenance. Confirm the URL and whether the same session continues into file execution or virtual machine shutdown.
Analyst notes
Investigating ESXi Curl or Wget Activity
curl and wget download a file or check a URL from the ESXi shell. The shell log records the command even when the binary is missing or the host has no route to the destination.
Possible investigation steps
- Read the URL and output path in message.
- Check the same session for a file under /tmp, chmod, or execution of the downloaded file.
- Confirm the URL with the virtualization owner.
False positive analysis
A documented download of a vendor package is commonly benign. A download of an unknown file into /tmp, followed by chmod, deserves review.
Response and remediation
- If the download was not approved, remove the file and end the shell session.
- Preserve shell.log and review commands issued after the download.