Skip to content

Open Files

Evidence: Open Files
Description: List Open Files
Category: System
Platform: esxi
Short Name: ofiles
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Open file descriptors on ESXi reveal active file access by processes, including VM disk files, configuration files, log files, and system resources. This snapshot captures what files were being accessed at collection time, providing evidence of process behavior and file manipulation.

This collector gathers structured data about open files.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses the output of system commands listing open file descriptors, extracting process IDs, file paths, file types, access modes, and file descriptor numbers for each open file on the ESXi host.

Open file data exposes active process file access patterns, helps identify processes accessing sensitive files, detects unauthorized file modifications in progress, and reveals temporary files or sockets used by malware. Cross-referencing with process data provides complete picture of file-based attacker activities.