
Summary
Detects when SSH is enabled on VMware ESXi hosts by monitoring ESXi-specific logs for messages indicating SSH activation (for example, "SSH access has been enabled" or the command "hostsvc/enable_ssh"). Enabling SSH provides a remote shell access path to the host, enabling potential file transfers to the datastore and remote command execution. This rule targets potential intruder activity after initial access, signaling possible lateral movement or persistence. Triage recommendations include verifying whether the hit corresponds to an approved change, inspecting source IP and user accounts involved in related authentication events, and checking for follow-on activity such as a CD /tmp, file uploads, or VM process executions. False positives arise when administrators legitimately enable SSH for troubleshooting and subsequently disable it; such events should be correlated with change tickets or documented procedures. Recommended response if unapproved: disable SSH (vim-cmd hostsvc/disable_ssh), preserve logs, rotate root passwords, and review accounts created during the window, then scan other hosts for the same event. The rule maps to MITRE ATT&CK T1021.004 (SSH) under TA0008 (Lateral Movement). Setup requires Elastic vSphere logs integration. References provide context on ESXi logging and related attack patterns.
Categories
- Infrastructure
- Endpoint
Data Sources
- File
ATT&CK Techniques
- T1021
- T1021.004
Created: 2026-09-30