ESXi Local Account Created
Detects creation of a local ESXi account. A new account is a separate login that remains after the session that created it. It has no rights until a role is assigned, and it is the first step toward a persistent login on the host.
Rule type: query
Rule indices:
- logs-vsphere.log-*
Rule Severity: medium
Risk Score: 47
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:
- https://lolesxi-project.github.io/LOLESXi/#
- https://blogs.vmware.com/security/2022/10/esxi-targeting-ransomware-tactics-and-techniques-part-2.html
- https://detect.fyi/vmware-esxi-logging-detection-opportunities-4fb56411ec21
Tags:
- Domain: Endpoint
- Data Source: VMware vSphere
- Use Case: Threat Detection
- Tactic: Persistence
- Resources: Investigation Guide
- Rule Type: Custom Query (KQL)
- Platform: VMware ESXi
- Threat: Ransomware
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Hostd records Account <name> was created on host <hostname> when an account is added from the Host Client or API. The shell records esxcli system account add. The new account has no role until a later permission change.
- Read the account name in message and the user field on the hostd event, which is the account that created it.
- Look for a following esxcli system permission set or an Admin role grant for the same account.
- Compare the account with the approved list for that host.
A documented joiner or break-glass account is commonly benign. An unknown account created by root over the Host Client, then granted Admin, deserves review.
- If the account was not approved, remove it with esxcli system account remove --id <name>.
- Preserve hostd.log and shell.log for the creating session.
data_stream.dataset:vsphere.log and event.module:vsphere and message:("esxcli system account add" or Account and "was created")
Framework: MITRE ATT&CK
Tactic:
- Name: Persistence
- Id: TA0003
- Reference URL: https://attack.mitre.org/tactics/TA0003/
Technique:
- Name: Create Account
- Id: T1136
- Reference URL: https://attack.mitre.org/techniques/T1136/
Sub Technique:
- Name: Local Account
- Id: T1136.001
- Reference URL: https://attack.mitre.org/techniques/T1136/001/