heroui logo

ESXi Firewall Disabled

Elastic Detection Rules

View Source
Summary
Detects ESXi firewall being turned off or set to default-allow by monitoring vsphere.log messages and related CLI flags. It looks for logs indicating 'Firewall has been disabled' or 'network firewall set' together with flags like '--default-action true' or '--default-action=true' or '--enabled false' or '--enabled=false', conditions that disable host-based filtering of management services. Because the ESXi firewall protects management interfaces, turning it off or making it permissive can allow subsequent connections to bypass controls. The rule uses the Elastic vSphere integration (vsphere.log) and is implemented as a custom query aligned with MITRE ATT&CK tactic Defense Evasion (T1562.004). Investigations should confirm whether the change was authorized, and correlate with SSH enablement, syslog changes, and VM lifecycle events. Remediation includes re-enabling the firewall and restoring the default action to DROP, reviewing related rule changes in the same session, and isolating the host and rotating credentials if the change was unauthorized.
Categories
  • Endpoint
  • On-Premise
  • Infrastructure
Data Sources
  • Firewall
  • Application Log
ATT&CK Techniques
  • T1562
  • T1562.004
Created: 2026-09-30