Skip to content

PCI Info

Evidence: PCI Info
Description: ESXi PCI Info
Category: DiskFilesystem
Platform: esxi
Short Name: pciinfo
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

PCI device enumeration provides comprehensive hardware inventory including network cards, storage controllers, GPUs, and other expansion devices. This baseline establishes expected hardware configuration and helps detect unauthorized physical device additions or modifications.

This collector gathers structured data about pci info.

FieldDescriptionExample
AddressAddressExample value
SegmentSegmentExample value
BusBusExample value
SlotSlotExample value
FunctionFunctionExample value
VMKernelNameVM Kernel NameExample value
VendorNameVendor NameExample value
DeviceNameDevice NameExample value
ConfiguredOwnerConfigured OwnerExample value
CurrentOwnerCurrent OwnerExample value
VendorIDVendor IDExample value
DeviceIDDevice IDExample value
SubVendorIDSub Vendor IDExample value
SubDeviceIDSub Device IDExample value
DeviceClassDevice ClassExample value
DeviceClassNameDevice Class NameExample value
ProgrammingInterfaceProgramming InterfaceExample value
RevisionIDRevision IDExample value
InterruptLineInterrupt LineExample value
IRQIRQ123
InterruptVectorInterrupt VectorExample value
PCIPinPCI PinExample value
SpawnedBusSpawned BusExample value
FlagsFlagsExample value
ModuleIDModule ID123
ModuleNameModule NameExample value
ChassisChassis123
PhysicalSlotPhysical Slot123
SlotDescriptionSlot DescriptionExample value
DeviceLayerBusAddressDevice Layer Bus AddressExample value
PassThruCapablePass Thru CapableExample value
ParentDeviceParent DeviceExample value
DependentDeviceDependent DeviceExample value
ResetMethodReset MethodExample value
FPTSharableFPT SharableExample value
NUMANodeNUMA Node123
ExtendedDeviceIDExtended Device ID123
ExtendedDeviceNameExtended Device NameExample value

This collector parses PCI device information, extracting bus addresses, device IDs, vendor IDs, device classes, subsystem information, driver associations, and device names for all PCI and PCIe devices visible to the ESXi host.

PCI device inventory validates hardware configuration, detects rogue devices like hardware keyloggers or network taps, identifies unauthorized passthrough configurations, and reveals hardware-based attack vectors. Device ID changes or unexpected additions indicate physical tampering or malicious hardware implants.