A ransomware operator who reaches an ESX host does not need long. Enumerate the VMs, kill them, encrypt the datastore. That sequence takes minutes, and it does not care whether anyone is watching. Any security model that depends on an analyst seeing an alert, triaging it, and deciding what to do is already too slow at that layer, and that assumes the SOC had hypervisor telemetry to begin with. Most do not.  

That is why we built ZeroLock as a preemptive control rather than another alerting product. It runs on the host, decides locally, and acts on the timescale of the attack instead of the timescale of a ticket queue. 

 

What Prevention Looks Like on the Host

Four capabilities do the work:

  • MFA on privileged operations. A behavioral rule can require a TOTP code before a governed action runs, so a stolen root credential does not buy an attacker file access, program execution, or network egress on the hypervisor. 
  • Exploit prevention and virtual patching. VM escape and VMX boundary CVEs get blocked at the behavioral level. That matters because almost nobody can take a maintenance window on a hypervisor the week a CVE drops.  
  • Local behavioral detection. Compact models run inside the agent and evaluate process and system behavior on the host itself. No cloud round trip, no waiting on a lookup to come back.  
  • Automated response and rollback. Attacks get terminated in progress and encrypted files restored, with no analyst in the loop. 

 

Now Your SOC Can See It

Prevention that nobody can observe is hard to trust and harder to report on. Vali Cyber is now a CrowdStrike Marketplace partner, and ZeroLock streams its enforcement and detection events into CrowdStrike Falcon® Next-Gen SIEM through HEC (HTTP Event Connector).  

These are not alerts asking an analyst to go decide something. They are records of attacks  ZeroLock already stopped at the hypervisor, normalized to the CrowdStrike Parsing Standard, and mapped to ECS so they correlate against endpoint and identity data from the Falcon platform on arrival. Your team gets the audit trail, the hunting surface, and the reporting, without inheriting a new response burden. Setup is a standard HEC connection for the endpoint.  

 

One Hypervisor Today, Maybe Another Tomorrow

Plenty of environments run one hypervisor and never touch it again. Others are mid-migration. ZeroLock is licensed by protected CPU core rather than by host, and those licenses transfer across platforms, so if you move, your protection moves with you and stays on through the cutover itself. That window is when an environment is least stable and least monitored, which is a bad time to lose coverage.  

Supported platforms include VMware Cloud Foundation 9.x and ESX 6.7 and up, including XenServer 6.5+, Citrix Hypervisor 8.0+, Proxmox, Red Hat Enterprise Virtualization, HPE Morpheus, Dell VxRail, and KVM on kernel 3.5 and up.  

 

Final Thoughts

The industry spent a decade tuning detection and response. It works on endpoints, where you have minutes to react and someone can pull a laptop off the network. The hypervisor gives you neither. You cannot isolate a host running half of production, and by the time the alert is triaged, the datastore is already encrypted. Prevention is the model that fits the tier.  

If you run Falcon Next-Gen SIEM and virtualized infrastructure, the listing is live in the CrowdStrike Marketplace under Vali Cyber. Reach out through valicyber.com if you want to watch a real attack chain stopped at machine speed.