
Summary
Detects three host level changes on a single ESXi host within a one hour window: enabling SSH access, disabling ExecInstalledOnly, and performing a VIB installation with force and no signature check. The combination enables remote shell, allows unsigned code to run, and bypasses VIB signature checks. The rule aggregates events per host and fires only when all three conditions occur within the same hour, reducing noise from isolated actions. It targets defense evasion and trust manipulation by enabling remote access and unsigned installations, which may precede deployment of a malicious or unauthorized package. Analysts should review the collected messages, ensure the VIB name matches an approved image, and correlate with change tickets. False positives can occur during documented maintenance windows when SSH is enabled and a vendor VIB is installed; verify the ticket and VIB identity before treating as malicious. Remediation: disable SSH when remote shell access is no longer required, re enable ExecInstalledOnly, remove unapproved VIBs, rotate credentials, and preserve logs for investigation.
Categories
- Infrastructure
Data Sources
- Application Log
ATT&CK Techniques
- T1562
- T1562.001
- T1553
- T1553.006
- T1021
- T1021.004
Created: 2026-09-30