﻿---
title: ESXi Local Account Created
description: Detects creation of a local ESXi account. A new account is a separate login that remains after the session that created it. It has no rights until a role...
url: https://www.elastic.co/elastic/docs-builder/docs/4384/reference/security/prebuilt-rules/rules/integrations/vsphere/persistence_esxi_account_created
products:
  - Elastic Security
---

# ESXi Local Account Created
Detects creation of a local ESXi account. A new account is a separate login that remains after the session that
created it. It has no rights until a role is assigned, and it is the first step toward a persistent login on the host.
**Rule type**: query
**Rule indices**:
- logs-vsphere.log-*

**Rule Severity**: medium
**Risk Score**: 47
**Runs every**: 
**Searches indices from**: `now-9m`
**Maximum alerts per execution**: 100
**References**:
- [[https://lolesxi-project.github.io/LOLESXi/#](https://lolesxi-project.github.io/LOLESXi/#)](https://lolesxi-project.github.io/LOLESXi/#)
- [[https://blogs.vmware.com/security/2022/10/esxi-targeting-ransomware-tactics-and-techniques-part-2.html](https://blogs.vmware.com/security/2022/10/esxi-targeting-ransomware-tactics-and-techniques-part-2.html)](https://blogs.vmware.com/security/2022/10/esxi-targeting-ransomware-tactics-and-techniques-part-2.html)
- [[https://detect.fyi/vmware-esxi-logging-detection-opportunities-4fb56411ec21](https://detect.fyi/vmware-esxi-logging-detection-opportunities-4fb56411ec21)](https://detect.fyi/vmware-esxi-logging-detection-opportunities-4fb56411ec21)

**Tags**:
- Domain: Endpoint
- Data Source: VMware vSphere
- Use Case: Threat Detection
- Tactic: Persistence
- Resources: Investigation Guide
- Rule Type: Custom Query (KQL)
- Platform: VMware ESXi
- Threat: Ransomware

**Version**: 1
**Rule authors**:
- Elastic

**Rule license**: Elastic License v2

## Setup

This rule requires ESXi host logs collected by the Elastic vSphere integration: [https://www.elastic.co/docs/reference/integrations/vsphere](https://www.elastic.co/docs/reference/integrations/vsphere)

## Investigation guide


## Triage and analysis


### Investigating ESXi Local Account Created

Hostd records Account <name> was created on host <hostname> when an account is added from the Host Client or API. The shell records esxcli system account add. The new account has no role until a later permission change.

#### Possible investigation steps

- Read the account name in message and the user field on the hostd event, which is the account that created it.
- Look for a following esxcli system permission set or an Admin role grant for the same account.
- Compare the account with the approved list for that host.


### False positive analysis

A documented joiner or break-glass account is commonly benign. An unknown account created by root over the Host Client, then granted Admin, deserves review.

### Response and remediation

- If the account was not approved, remove it with esxcli system account remove --id <name>.
- Preserve hostd.log and shell.log for the creating session.


## Rule Query

```kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("esxcli system account add" or Account and "was created")
```

**Framework:** MITRE ATT&CK
- Tactic:
  - Name: Persistence
- Id: TA0003
- Reference URL: [[https://attack.mitre.org/tactics/TA0003/](https://attack.mitre.org/tactics/TA0003/)](https://attack.mitre.org/tactics/TA0003/)
- Technique:
  - Name: Create Account
- Id: T1136
- Reference URL: [[https://attack.mitre.org/techniques/T1136/](https://attack.mitre.org/techniques/T1136/)](https://attack.mitre.org/techniques/T1136/)
- Sub Technique:
  - Name: Local Account
- Id: T1136.001
- Reference URL: [[https://attack.mitre.org/techniques/T1136/001/](https://attack.mitre.org/techniques/T1136/001/)](https://attack.mitre.org/techniques/T1136/001/)