Skip to content

Routes

Evidence: Routes
Description: List Routes
Category: Network
Platform: esxi
Short Name: routes
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

ESXi network routing entries reflect layer-3 reachability and ARP neighbor state for the host. Understanding routes aids in mapping connectivity and potential egress paths.

This collector gathers structured data about routes.

FieldDescriptionExample
NeighborNeighborExample value
MACMACExample value
InterfaceInterfaceExample value
ExpiryExpiryExample value
TypeTypeExample value

This collector parses a pre-generated esx network routes text file and normalizes route neighbor, interface, MAC, expiry, and type fields.

Routing data provides network context for lateral movement, external communications, and validates expected network topology during investigations.