{"id":742,"date":"2025-11-18T18:39:30","date_gmt":"2025-11-18T18:39:30","guid":{"rendered":"https:\/\/www.dae-pro.fr\/blog\/?p=742"},"modified":"2025-11-18T18:39:31","modified_gmt":"2025-11-18T18:39:31","slug":"cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production","status":"publish","type":"post","link":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/","title":{"rendered":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Lorsqu\u2019un h\u00f4te VMware ESXi montre des signes d\u2019intrusion, la priorit\u00e9 est d\u2019emp\u00eacher la propagation tout en maintenant les services en ligne. \u00c9teindre brutalement l\u2019hyperviseur peut bloquer l\u2019activit\u00e9, provoquer des pertes de donn\u00e9es ou interrompre des machines virtuelles critiques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Heureusement, il existe des m\u00e9thodes permettant d\u2019<strong>isoler un serveur compromis<\/strong> sans stopper l\u2019ensemble du fonctionnement. L\u2019objectif : limiter les risques, contenir l\u2019attaque et pr\u00e9server l\u2019acc\u00e8s aux machines virtuelles saines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Identifier rapidement un h\u00f4te compromis<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Avant tout, il faut d\u00e9tecter les signes montrant que l\u2019hyperviseur est affect\u00e9 :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>sessions Shell ouvertes sans autorisation<\/li>\n\n\n\n<li>pics d\u2019activit\u00e9 inhabituels sur les datastores<\/li>\n\n\n\n<li>t\u00e2ches planifi\u00e9es non pr\u00e9vues<\/li>\n\n\n\n<li>fichiers syst\u00e8me modifi\u00e9s<\/li>\n\n\n\n<li>comportements suspects dans \/var\/log<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Une fois la compromission confirm\u00e9e, l\u2019\u00e9tape suivante est l\u2019isolement contr\u00f4l\u00e9.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b01 : isoler l\u2019h\u00f4te via sa carte de gestion (pas les VM)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">L\u2019objectif est de <strong>d\u00e9sactiver uniquement la connectivit\u00e9 de l\u2019hyperviseur<\/strong> tout en laissant les machines virtuelles continuer \u00e0 \u00e9mettre et recevoir du trafic.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u00c9tapes recommand\u00e9es<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Acc\u00e9der au <strong>switch physique<\/strong> o\u00f9 est branch\u00e9e la carte de gestion ESXi (Management Network).<\/li>\n\n\n\n<li>D\u00e9sactiver <strong>uniquement<\/strong> le port physique utilis\u00e9 pour vmk0 (Management Network).<\/li>\n\n\n\n<li>V\u00e9rifier que les ports uplink associ\u00e9s aux groupes de ports des VM <strong>restent actifs<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">R\u00e9sultat :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Plus aucun acc\u00e8s SSH, API ou vCenter sur l\u2019h\u00f4te compromis.<\/li>\n\n\n\n<li>Les machines virtuelles, elles, continuent de communiquer normalement.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Cette approche coupe le lien administratif sans impacter la production.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b02 : passer l\u2019h\u00f4te en \u201cquarantine mode\u201d dans un cluster vSphere<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Si l\u2019infrastructure utilise vSphere HA ou DRS, une option peu connue permet de bloquer l\u2019h\u00f4te sans arr\u00eater les VM.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Fonctionnement<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Le <strong>quarantine mode<\/strong> limite le placement de nouvelles VM sur l\u2019h\u00f4te et r\u00e9duit les interactions avec le cluster, tout en gardant les VM actives.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Utilit\u00e9 en cas d\u2019incident<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>r\u00e9duit la surface d\u2019interaction de l\u2019h\u00f4te<\/li>\n\n\n\n<li>emp\u00eache le d\u00e9placement de nouvelles VM<\/li>\n\n\n\n<li>laisse tourner uniquement le minimum n\u00e9cessaire<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">C\u2019est un confinement doux, adapt\u00e9 en cas de suspicion d\u2019activit\u00e9 malveillante.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b03 : d\u00e9connecter l\u2019h\u00f4te du vCenter (sans l\u2019\u00e9teindre)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Supprimer temporairement la connexion entre vCenter et l\u2019hyperviseur emp\u00eache tout attaquant ayant compromis les API de prendre le contr\u00f4le du cluster.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u00c9tapes<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ouvrir vCenter<\/li>\n\n\n\n<li>S\u00e9lectionner l\u2019h\u00f4te &gt; <strong>Disconnect<\/strong><\/li>\n\n\n\n<li>Confirmer la d\u00e9sactivation<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Cons\u00e9quences :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>plus aucune t\u00e2che distante ne peut \u00eatre d\u00e9clench\u00e9e sur l\u2019h\u00f4te<\/li>\n\n\n\n<li>les machines virtuelles restent en activit\u00e9<\/li>\n\n\n\n<li>l\u2019hyperviseur fonctionne en mode autonome jusqu\u2019\u00e0 r\u00e9int\u00e9gration<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Utile lorsque l\u2019attaque semble exploit\u00e9e via vCenter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b04 : isoler le trafic de gestion via un VLAN temporaire<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Si l\u2019\u00e9quipe r\u00e9seau peut intervenir rapidement, l\u2019une des m\u00e9thodes les plus propres consiste \u00e0 <strong>basculer le Management Network dans un VLAN isol\u00e9<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Avantages<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>l\u2019h\u00f4te devient invisible depuis les autres VLAN<\/li>\n\n\n\n<li>seules les VM continuent \u00e0 communiquer sur leurs segments normaux<\/li>\n\n\n\n<li>possibilit\u00e9 de contr\u00f4ler les flux au niveau firewall<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Id\u00e9al lorsque l\u2019infrastructure est d\u00e9j\u00e0 segment\u00e9e.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b05 : neutraliser temporairement les services sensibles de l\u2019hyperviseur<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">VMware ESXi autorise la d\u00e9sactivation cibl\u00e9e de services critiques susceptibles d\u2019\u00eatre exploit\u00e9s :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SSH<\/strong><\/li>\n\n\n\n<li><strong>ESXi Shell<\/strong><\/li>\n\n\n\n<li><strong>vpxa<\/strong> (agent vCenter)<\/li>\n\n\n\n<li><strong>hostd<\/strong> (gestion locale)<\/li>\n\n\n\n<li><strong>DCUI<\/strong> (interface console)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">En d\u00e9sactivant ces services :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>l\u2019attaquant perd les points d\u2019acc\u00e8s privil\u00e9gi\u00e9s<\/li>\n\n\n\n<li>les machines virtuelles restent stables<\/li>\n\n\n\n<li>l\u2019h\u00f4te continue \u00e0 faire tourner les workloads actifs<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u00c0 manipuler avec prudence, mais tr\u00e8s efficace en phase d\u2019urgence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>M\u00e9thode n\u00b06 : conserver les VM en ligne tout en fermant l\u2019uplink probl\u00e9matique<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Si l\u2019intrusion semble transiter par un uplink r\u00e9seau sp\u00e9cifique (dans un vSwitch), il est possible de couper uniquement ce lien sans affecter les VM utilisant d\u2019autres uplinks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Exemple :<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Uplink1 = trafic de gestion<\/li>\n\n\n\n<li>Uplink2 = trafic VM<\/li>\n\n\n\n<li>Uplink3 = trafic de stockage<\/li>\n\n\n\n<li>Uplink4 = vMotion<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Couper <strong>uniquement<\/strong> Uplink1 isole la surface sensible tout en pr\u00e9servant le reste.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Points de vigilance lors de l\u2019isolement<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pour \u00e9viter des effets de bord :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>v\u00e9rifier que les datastores utilis\u00e9s par les VM ne d\u00e9pendent pas du m\u00eame uplink que la gestion<\/li>\n\n\n\n<li>s\u2019assurer que les VM critiques disposent d\u2019un second uplink<\/li>\n\n\n\n<li>ne pas couper les ports reli\u00e9s aux SAN\/NAS<\/li>\n\n\n\n<li>\u00e9viter de d\u00e9connecter l\u2019h\u00f4te si r\u00e9int\u00e9gration vCenter risque de poser probl\u00e8me (ex : version mismatch)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Un isolement mal r\u00e9alis\u00e9 peut entra\u00eener la perte d\u2019acc\u00e8s au stockage, ce qui causerait l\u2019arr\u00eat des VM malgr\u00e9 l\u2019objectif initial.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Apr\u00e8s l\u2019isolement : proc\u00e9dures de stabilisation<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Une fois l\u2019h\u00f4te s\u00e9par\u00e9 du r\u00e9seau sensible :<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Sauvegarder les logs<\/strong> (\/var\/log\/*)<\/li>\n\n\n\n<li><strong>Exporter la configuration<\/strong> de l\u2019hyperviseur pour analyse<\/li>\n\n\n\n<li>Scanner les fichiers du datastore pour identifier\n<ul class=\"wp-block-list\">\n<li>scripts suspects<\/li>\n\n\n\n<li>snapshots anormaux<\/li>\n\n\n\n<li>fichiers .sh, .py, .so non officiels<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>V\u00e9rifier les t\u00e2ches planifi\u00e9es dans crontab<\/li>\n\n\n\n<li>Comparer l\u2019int\u00e9grit\u00e9 des fichiers syst\u00e8me (\/etc) avec un h\u00f4te sain<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">L\u2019objectif est de comprendre l\u2019origine de l\u2019infiltration avant une remise en service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A LIRE AUSSI <a href=\"https:\/\/www.dae-pro.fr\/blog\/iso-27001-verifier-que-vos-procedures-informatiques-sont-conformes\/\" target=\"_blank\" rel=\"noreferrer noopener\">ISO 27001 : v\u00e9rifier que vos proc\u00e9dures informatiques sont conformes<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Quand faut-il \u00e9teindre l\u2019h\u00f4te malgr\u00e9 tout ?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">L\u2019arr\u00eat complet est n\u00e9cessaire uniquement lorsque :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>les datastores chiffr\u00e9s commencent \u00e0 \u00eatre alt\u00e9r\u00e9s<\/li>\n\n\n\n<li>l\u2019hyperviseur ex\u00e9cute un binaire inconnu au niveau syst\u00e8me<\/li>\n\n\n\n<li>les VM montrent des signes directs de compromission<\/li>\n\n\n\n<li>les acc\u00e8s stockage sont affect\u00e9s<\/li>\n\n\n\n<li>l\u2019attaquant a acquis un acc\u00e8s root persistant non contr\u00f4lable<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Si ces signes apparaissent, l\u2019isolation ne suffit plus.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lorsqu\u2019un h\u00f4te VMware ESXi montre des signes d\u2019intrusion, la priorit\u00e9 est d\u2019emp\u00eacher la propagation tout en maintenant les services en ligne. \u00c9teindre brutalement l\u2019hyperviseur peut<\/p>\n","protected":false},"author":2,"featured_media":743,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-742","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-securite"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro\" \/>\n<meta property=\"og:description\" content=\"Lorsqu\u2019un h\u00f4te VMware ESXi montre des signes d\u2019intrusion, la priorit\u00e9 est d\u2019emp\u00eacher la propagation tout en maintenant les services en ligne. \u00c9teindre brutalement l\u2019hyperviseur peut\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/\" \/>\n<meta property=\"og:site_name\" content=\"DAE-Pro\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-18T18:39:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-18T18:39:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sarah D.\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sarah D.\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/\"},\"author\":{\"name\":\"Sarah D.\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#\\\/schema\\\/person\\\/cc910843c609c85b5d15d0751ce8356a\"},\"headline\":\"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0?\",\"datePublished\":\"2025-11-18T18:39:30+00:00\",\"dateModified\":\"2025-11-18T18:39:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/\"},\"wordCount\":980,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg\",\"articleSection\":[\"Cyber-s\u00e9curit\u00e9\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/\",\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/\",\"name\":\"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg\",\"datePublished\":\"2025-11-18T18:39:30+00:00\",\"dateModified\":\"2025-11-18T18:39:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg\",\"contentUrl\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg\",\"width\":1200,\"height\":675,\"caption\":\"Cyberattaque comment isoler un serveur compromis sous VMware ESXi sans couper la production\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/\",\"name\":\"DAE-Pro\",\"description\":\"S\u00e9curit\u00e9 des biens, personnes &amp; donn\u00e9es d&#039;entreprise\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#organization\",\"name\":\"DAE-Pro\",\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/DAE-pro-2.png\",\"contentUrl\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/DAE-pro-2.png\",\"width\":595,\"height\":140,\"caption\":\"DAE-Pro\"},\"image\":{\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/#\\\/schema\\\/person\\\/cc910843c609c85b5d15d0751ce8356a\",\"name\":\"Sarah D.\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g\",\"caption\":\"Sarah D.\"},\"url\":\"https:\\\/\\\/www.dae-pro.fr\\\/blog\\\/author\\\/sara\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/","og_locale":"fr_FR","og_type":"article","og_title":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro","og_description":"Lorsqu\u2019un h\u00f4te VMware ESXi montre des signes d\u2019intrusion, la priorit\u00e9 est d\u2019emp\u00eacher la propagation tout en maintenant les services en ligne. \u00c9teindre brutalement l\u2019hyperviseur peut","og_url":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/","og_site_name":"DAE-Pro","article_published_time":"2025-11-18T18:39:30+00:00","article_modified_time":"2025-11-18T18:39:31+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg","type":"image\/jpeg"}],"author":"Sarah D.","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Sarah D.","Dur\u00e9e de lecture estim\u00e9e":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#article","isPartOf":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/"},"author":{"name":"Sarah D.","@id":"https:\/\/www.dae-pro.fr\/blog\/#\/schema\/person\/cc910843c609c85b5d15d0751ce8356a"},"headline":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0?","datePublished":"2025-11-18T18:39:30+00:00","dateModified":"2025-11-18T18:39:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/"},"wordCount":980,"commentCount":0,"publisher":{"@id":"https:\/\/www.dae-pro.fr\/blog\/#organization"},"image":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg","articleSection":["Cyber-s\u00e9curit\u00e9"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/","url":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/","name":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0? - DAE-Pro","isPartOf":{"@id":"https:\/\/www.dae-pro.fr\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#primaryimage"},"image":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg","datePublished":"2025-11-18T18:39:30+00:00","dateModified":"2025-11-18T18:39:31+00:00","breadcrumb":{"@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#primaryimage","url":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg","contentUrl":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/11\/Cyberattaque-comment-isoler-un-serveur-compromis-sous-VMware-ESXi-sans-couper-la-production-.jpg","width":1200,"height":675,"caption":"Cyberattaque comment isoler un serveur compromis sous VMware ESXi sans couper la production"},{"@type":"BreadcrumbList","@id":"https:\/\/www.dae-pro.fr\/blog\/cyberattaque-comment-isoler-un-serveur-compromis-sous-vmware-esxi-sans-couper-la-production\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.dae-pro.fr\/blog\/"},{"@type":"ListItem","position":2,"name":"Cyberattaque : comment isoler un serveur compromis sous VMware ESXi sans couper la production\u00a0?"}]},{"@type":"WebSite","@id":"https:\/\/www.dae-pro.fr\/blog\/#website","url":"https:\/\/www.dae-pro.fr\/blog\/","name":"DAE-Pro","description":"S\u00e9curit\u00e9 des biens, personnes &amp; donn\u00e9es d&#039;entreprise","publisher":{"@id":"https:\/\/www.dae-pro.fr\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dae-pro.fr\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.dae-pro.fr\/blog\/#organization","name":"DAE-Pro","url":"https:\/\/www.dae-pro.fr\/blog\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.dae-pro.fr\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/09\/DAE-pro-2.png","contentUrl":"https:\/\/www.dae-pro.fr\/blog\/wp-content\/uploads\/2025\/09\/DAE-pro-2.png","width":595,"height":140,"caption":"DAE-Pro"},"image":{"@id":"https:\/\/www.dae-pro.fr\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.dae-pro.fr\/blog\/#\/schema\/person\/cc910843c609c85b5d15d0751ce8356a","name":"Sarah D.","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/36b6782aaa2ed3e4572514c64e2957724bcdc2df9fd7944b47e85c9ebbf62465?s=96&d=mm&r=g","caption":"Sarah D."},"url":"https:\/\/www.dae-pro.fr\/blog\/author\/sara\/"}]}},"_links":{"self":[{"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/posts\/742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/comments?post=742"}],"version-history":[{"count":1,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/posts\/742\/revisions"}],"predecessor-version":[{"id":744,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/posts\/742\/revisions\/744"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/media\/743"}],"wp:attachment":[{"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/media?parent=742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/categories?post=742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dae-pro.fr\/blog\/wp-json\/wp\/v2\/tags?post=742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}