heroui logo

ESXi Audit Records Disabled

Elastic Detection Rules

View Source
Summary
This rule detects when ESXi audit record transmission is disabled, either on the host itself or to a remote collector. Disabling audit records hides subsequent administrative actions (such as changes to accounts, firewall configurations, and SSH activity). The detection looks in the Elastic vSphere data stream (data_stream.dataset: vsphere.log) for messages containing auditrecords with indicators like --enabled false, --enabled=false, local disable, or remote disable. When matched, it raises a detection with a medium severity and risk score of 47. It maps to MITRE ATT&CK technique T1562.001 (Disable or Modify Tools) under Defense Evasion. The rule is implemented as a Custom Query (KQL) against the vsphere.log data, with guidance on investigation, false positives, and remediation provided in the rule description and setup sections.
Categories
  • Infrastructure
Data Sources
  • Application Log
ATT&CK Techniques
  • T1562
  • T1562.001
Created: 2026-09-30