Skip to content

VmkNicList

Evidence: VmkNicList
Description: List VmkNicList
Category: Network
Platform: esxi
Short Name: vmkniclist
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

VMkernel network interfaces (vmknic) provide ESXi management, vMotion, storage, and fault tolerance network connectivity. These interfaces are critical for hypervisor operations and can be targets for network-based attacks or misconfigurations that expose management networks.

This collector gathers structured data about vmkniclist.

FieldDescriptionExample
InterfaceInterfaceExample value
PortGroupPort GroupExample value
IPFamilyIP FamilyExample value
IPAddressIP AddressExample value
NetmaskNetmaskExample value
BroadcastBroadcastExample value
MACMACExample value
MTUMTU123
TSOMSSTSOMSS123
EnabledEnabledExample value
TypeTypeExample value
NetStackNet StackExample value

This collector parses VMkernel NIC information, extracting interface names, DHCP/IPv6 settings, IP addresses, MAC addresses, MTU sizes, TSO/MSS values, enabled status, interface types, and network stack assignments for each configured VMkernel adapter.

VMkernel interface configuration reveals management network topology, potential security misconfigurations, and unauthorized network modifications. Analyzing IP assignments, MAC addresses, and network stack associations helps detect rogue interfaces, validate network isolation, and identify attack vectors targeting hypervisor management.