
Summary
This rule detects changes to the ESXi root password by reviewing vSphere logs for credential updates affecting the root account. It specifically matches events that indicate a password was changed for the root account or the ESXi CLI command esxcli system account set -i root, which result in the old password being replaced and the new credentials gaining full control over the host. The detection uses data_stream.dataset:vsphere.log and event.module:vsphere with a message pattern targeting these indicators. When triggered, it maps to MITRE ATT&CK technique T1098 (Account Manipulation) under Persistence (TA0003), signaling potential unauthorized or unapproved credential changes that could enable continued access to SSH, the Host Client, and the API. Investigations should validate whether the change was approved (change ticket, break-glass log, or documented rotation), and correlate with host security posture such as lockdown mode status, new local accounts, or elevated permissions granted in the same session. False positives can arise from legitimate administrator password rotations during maintenance if properly documented in change records and secret stores. Recommended triage steps include reviewing the corresponding hostd.log and shell.log entries, confirming the identity of the actor who performed the change, verifying the secret vault entry, and ensuring the change is reflected in the organization’s break-glass process. Remediation for unapproved changes includes resetting the root password, re-securing access, and preserving relevant logs for forensics. Setup requires Elastic’s vSphere integration to collect ESXi host logs.
Categories
- Infrastructure
Data Sources
- File
ATT&CK Techniques
- T1098
Created: 2026-09-30