
Summary
Detects ESXi host activity where a file is granted execute permissions via chmod, including symbolic (+x) and numeric modes (e.g., 755, 777). The rule targets events logged by the Elastic vSphere integration (vsphere.log) where the message contains chmod and a recognized execute-bit form. On ESXi, making a file executable (often in /tmp) can enable a later payload execution against the datastore, making this a notable step in ransomware or other privilege-escalation efforts. The rule maps to MITRE ATT&CK T1222.002 (Linux/macOS File and Directory Permissions Modification) under Defense Evasion (TA0005). It is designed to flag potential post-dropped-file execution preparations rather than routine admin activity. The detection uses a KQL query against the vsphere data stream (data_stream.dataset:vsphere.log, event.module:vsphere) with patterns for various execute-bit representations (e.g., +x, 0777, 0755, etc.). The rule window is from now-9m, enabling near-term detection. Risk score is 47 and severity is medium, with metadata indicating ESXi/VMware vSphere as the data source and threat focus on ransomware.
Categories
- Endpoint
- Linux
- Infrastructure
Data Sources
- File
- Process
ATT&CK Techniques
- T1222
- T1222.002
Created: 2026-09-30