heroui logo

ESXi System and Account Enumeration

Elastic Detection Rules

View Source
Summary
This rule detects ESXi host information and local account enumeration by monitoring vsphere logs for shell commands that reveal system details. It looks for commands that collect OS build/version (uname -a, esxcli system version get) and hostname, as well as listing local accounts (esxcli system account list). The output helps identify which accounts exist on the host prior to potential credential changes or misuse. The detection uses the vsphere.log data stream from the Elastic vSphere integration and is implemented as a Custom Query (KQL) across the logs. The rule assigns a risk score of 21 with low severity, consistent with Discovery activity that could indicate reconnaissance. It maps to MITRE ATT&CK techniques: T1082 (System Information Discovery) and T1087.001 (Local Account) under TA0007 (Discovery). Investigators should verify which command ran, check for related VM process activity, and compare listed accounts against known host accounts. The rule includes specific triage steps, false positive notes about legitimate inventory or troubleshooting activity, and remediation guidance (isolate the host if the session also manipulates VMs or writes to /tmp; otherwise log the involved accounts and source for broader hunting). Setup requires ESXi host logs collected via the Elastic vSphere integration. Overall, the rule helps detect early discovery activity that could precede credential abuse or ransomware actions on ESXi hosts.
Categories
  • Infrastructure
  • Endpoint
Data Sources
  • Command
  • Process
ATT&CK Techniques
  • T1082
  • T1087
  • T1087.001
Created: 2026-09-30