
Summary
Detects ESXi hostd accepting the root password from a remote address, which results in full control of the host via the Host Client or API. Local 127.0.0.1 sessions are excluded to avoid noise from host-local operations. The rule searches vSphere logs for an authentication success message containing “Accepted password for user root” while excluding events originating from 127.0.0.1. A remote root login can indicate credential compromise and potential ransomware-related activity via initial access or subsequent lateral movement. The rule maps to MITRE ATT&CK T1078 (Valid Accounts) with T1078.001 (Default Accounts) under TA0001 (Initial Access). It relies on ESXi log data collected by the Elastic vSphere integration (vsphere.log) and is effective within a recent window (from now-9m) to minimize historical noise. False positives include legitimate maintenance sign-ins from known workstations; tampering with SSH enablement or file activity around /tmp or /vmfs/volumes shortly after login can indicate abuse. Triage should verify the source IP against known admin workstations, correlate with related events (e.g., “root@<ip>” sessions or SSH enablement), and review shell activity and VMFS operations that may follow. Remediation includes terminating the session if unapproved, rotating the root password, auditing accounts created in that window, and preserving hostd logs for investigation. Reference guides and setup notes emphasize using the Elastic vSphere integration to feed ESXi logs into the detection pipeline.
Categories
- Infrastructure
Data Sources
- Logon Session
- File
ATT&CK Techniques
- T1078
- T1078.001
Created: 2026-09-30