> For the complete documentation index, see [llms.txt](https://0xpthree.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xpthree.gitbook.io/notes/post-exploit/vmware/disk-encryption.md).

# Disk Encryption

Check if a VM's disk is encrypted in VMware. If not you can make a clone of the VM, without affecting the current running state, and then download the `.vmdk` to harvest any interesting data within.&#x20;

It is also possible to extract disks from snapshots, if there are any.

1. Verify encryption in vSphere Web Client. In the VM's Summary tab, look for Encryption status.

<figure><img src="/files/TFjtKZP2jYEMUGKCzbAC" alt=""><figcaption></figcaption></figure>

2. Verify encryption through the CLI.

```bash
## Use vim-cmd, look for "encryption"
$ vim-cmd vmsvc/get.summary <VMID>

## Check VM's configuration file (.vmx)
cat /vmfs/volumes/<datastore>/<vm_folder>/<vm_name>.vmx | grep "encryption"
```
