Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
Description
Detects any creation or modification to a windows domain group with the name "ESX Admins". This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor. VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
Query · sigma
selection: EventID: - 4727 - 4728 - 4731 - 4737 - 4754 - 4755 - 4756 keyword_group: - ESX Admins condition: selection and keyword_group
Known false positives
- Unknown