
Summary
This rule detects when ESXi audit record transmission is disabled, either on the host itself or to a remote collector. Disabling audit records hides subsequent administrative actions (such as changes to accounts, firewall configurations, and SSH activity). The detection looks in the Elastic vSphere data stream (data_stream.dataset: vsphere.log) for messages containing auditrecords with indicators like --enabled false, --enabled=false, local disable, or remote disable. When matched, it raises a detection with a medium severity and risk score of 47. It maps to MITRE ATT&CK technique T1562.001 (Disable or Modify Tools) under Defense Evasion. The rule is implemented as a Custom Query (KQL) against the vsphere.log data, with guidance on investigation, false positives, and remediation provided in the rule description and setup sections.
Categories
- Infrastructure
Data Sources
- Application Log
ATT&CK Techniques
- T1562
- T1562.001
Created: 2026-09-30