Skip to content

Disk Usage

Evidence: Disk Usage
Description: ESXi Disk Usage
Category: DiskFilesystem
Platform: esxi
Short Name: diskusg
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

ESXi disk usage statistics track storage consumption across filesystems, partitions, and volumes on the hypervisor. Monitoring disk usage helps identify suspicious storage patterns, detect data staging for exfiltration, and reveal space exhaustion attacks or log file tampering.

This collector gathers structured data about disk usage.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses disk usage reports, extracting filesystem mount points, total capacity, used space, available space, usage percentages, and mount status for each storage volume accessible to the ESXi host.

Disk usage patterns reveal anomalous storage consumption that may indicate malware staging areas, log file manipulation to hide evidence, or denial-of-service attempts via disk exhaustion. Comparing usage trends helps identify rapid changes consistent with data exfiltration or malicious file placement.