heroui logo

ESXi Host Logs Deleted with rm

Elastic Detection Rules

View Source
Summary
This rule detects a shell command that deletes ESXi host log files, a common defense-evasion technique to erase traces of activity. It triggers when a log message indicates an rm operation targeting either a /var/log path or a log file name (*.log) in VMware vSphere logs. The detection leverages the Elastic vSphere integration data stream (vsphere.log) and matches messages via a Kuery query that looks for rm in conjunction with either an explicit log path or a wildcard log filename. The rule is mapped to MITRE ATT&CK as Indicator Removal (TA0005), specifically T1070 (Indicator Removal) with subtechniques T1070.002 (Clear Linux or Mac System Logs) and T1070.004 (File Deletion). This combination signals potential attempt to hide changes to the host by removing log evidence, including logs that capture shell commands, authentication events, and host activity (e.g., hostd logs). Investigation guidance emphasizes: extracting the exact path deleted from the alert, enumerating remaining files under /var/log on the ESXi host (such as hostd.log, auth.log, and related rotated logs), and correlating with other events in the index (account changes, firewall modifications, VM power events) that occurred in the same session. False positives may arise from legitimate maintenance, such as documented log rotation or deletion during a change window; verification with change tickets and the specific path is recommended. Remediation steps include isolating the host if the deletion is unauthorized, preserving logs before rotation, rotating credentials used in the session, and validating that remote syslog or alternative log collectors retain copies of the deleted logs. The rule’s setup notes require enabling the Elastic vSphere integration to collect ESXi host logs. The detection content also provides investigation fields (e.g., @timestamp, message, host.hostname, log.file.path) to aid correlation and response. Overall, this rule provides proactive visibility into potential tampering with ESXi host logs, enabling rapid containment and evidence preservation in cases of suspected log data deletion.
Categories
  • Linux
  • On-Premise
  • Infrastructure
  • Endpoint
Data Sources
  • Process
  • File
  • Command
ATT&CK Techniques
  • T1070
  • T1070.002
  • T1070.004
Created: 2026-09-30