ESXi Virtual Machine Snapshot Removed
Description
Detects removal of all snapshots for an ESXi virtual machine. Snapshots are on-host recovery points for a guest. Removing all of them deletes those recovery points, so the virtual machine cannot be reverted to an earlier disk state.
Query · kuery
data_stream.dataset: "vsphere.log" and ( message: "snapshot.removeall" )
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Snapshot consolidation after backups, storage pressure, and planned decommissioning can remove every snapshot for a VM. Confirm the account and whether the command ran against one VM or every VM.
Analyst notes
Investigating ESXi Virtual Machine Snapshot Removed
Snapshots are the local recovery point on a datastore. snapshot.removeall deletes them for one VM id. Ransomware wraps that command in a loop over every VM.
Possible investigation steps
- Read the VM id in message. A loop that calls removeall for every id from getallvms is higher severity than one VM.
- Check whether VM processes were killed or disks were enumerated in the same session.
- Ask the backup or virtualization owner whether snapshot consolidation was underway.
False positive analysis
Backup products and administrators delete snapshots after a successful consolidate. Match the account and the change ticket before closing the alert.
Response and remediation
- If removal was not approved, isolate the host and stop the shell session.
- Restore affected VMs from an off-host backup. Datastore snapshots removed by this command are gone.
- Preserve shell history and hostd logs.