ESXi Forensics and the RAMdisk Logging Gap Nobody Configured Around
On ESXi the logs that explain how an intruder got root are written to a ramdisk that a reboot erases. Here is where the evidence actually lives, what to detect before it’s gone, and how it maps to the audit-storage controls the architecture violates by default.