Skip to content

Environment Variables

Evidence: Environment Variables
Description: ESXi Environment Variables
Category: System
Platform: esxi
Short Name: envvar
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Environment variables in ESXi control process execution contexts, system paths, configuration locations, and runtime behavior. Attackers may inject malicious paths, proxy settings, or library preloads via environment variables to enable persistence or hijack system processes.

This collector gathers structured data about environment variables.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses system environment variables, extracting variable names and their assigned values from the ESXi shell environment and system-wide configuration contexts.

Environment variable analysis reveals configuration tampering, malicious PATH manipulations, suspicious LD_PRELOAD entries, unauthorized proxy configurations, and other environment-based persistence mechanisms. Comparing against baselines identifies unauthorized modifications that enable privilege escalation or process hijacking.