ESXi Virtual Machine Powered Off
Description
Detects vim-cmd vmsvc/power.off on an ESXi host. Powering a virtual machine off releases the lock the hypervisor
holds on its virtual disks. With the guest stopped, those disks can be rewritten or encrypted while the machine
is down.
Query · kuery
data_stream.dataset: "vsphere.log" and ( message: "vmsvc/power.off" )
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators power off virtual machines for patching, decommissioning, and hardware maintenance. Review the account and whether the command targeted one VM id or every id returned by `getallvms`.
Analyst notes
Investigating ESXi Virtual Machine Powered Off
vim-cmd vmsvc/power.off is the guest-aware shutdown path ransomware uses when esxcli vm process kill is not enough. A for loop over getallvms powers off every guest on the host.
Possible investigation steps
- Read message for a single VM id versus a loop over vim-cmd vmsvc/getallvms.
- Correlate with snapshot removal, vm process kill, and find commands for *.vmdk on the same host.
- Ask the VM owner whether that power-off was scheduled.
False positive analysis
One VM powered off by a known administrator during a change window is commonly benign. Powering off every VM in one shell loop is the ransomware pattern.
Response and remediation
- If the power-off was not approved, isolate the host and do not reboot it.
- Power guests back on only after confirming their disks were not encrypted, or restore them from backup.
- Preserve shell and hostd logs for the session that issued power.off.