ESXi Local Account Created

Detects creation of a local ESXi account. A new account is a separate login that remains after the session that created it. It has no rights until a role is assigned, and it is the first step toward a persistent login on the host.

Rule type: query
Rule indices:

  • logs-vsphere.log-*

Rule Severity: medium
Risk Score: 47
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:

Tags:

  • Domain: Endpoint
  • Data Source: VMware vSphere
  • Use Case: Threat Detection
  • Tactic: Persistence
  • Resources: Investigation Guide
  • Rule Type: Custom Query (KQL)
  • Platform: VMware ESXi
  • Threat: Ransomware

Version: 1
Rule authors:

  • Elastic

Rule license: Elastic License v2

This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere

Hostd records Account <name> was created on host <hostname> when an account is added from the Host Client or API. The shell records esxcli system account add. The new account has no role until a later permission change.

  • Read the account name in message and the user field on the hostd event, which is the account that created it.
  • Look for a following esxcli system permission set or an Admin role grant for the same account.
  • Compare the account with the approved list for that host.

A documented joiner or break-glass account is commonly benign. An unknown account created by root over the Host Client, then granted Admin, deserves review.

  • If the account was not approved, remove it with esxcli system account remove --id <name>.
  • Preserve hostd.log and shell.log for the creating session.
data_stream.dataset:vsphere.log and event.module:vsphere and message:("esxcli system account add" or Account and "was created")
		

Framework: MITRE ATT&CK