
Summary
Detects a successful SSH session opened by the privileged vpxuser account on ESXi hosts. vpxuser is a VMware vCenter Server service account used to manage ESXi hosts; an SSH session originating from this account directly to a host shell outside the vCenter management path indicates credential reuse or misuse with potential malicious intent. The rule relies on ESXi host logs ingested via the Elastic vSphere integration (vsphere.log) and matches messages containing the phrase 'SSH session was opened for' in conjunction with vpxuser. It maps to MITRE ATT&CK T1021.004 (SSH) under the Lateral Movement tactic and is labeled high severity. False positives are possible in rare break-glass or troubleshooting scenarios; recommended actions include verifying the source against change tickets, rotating the vpxuser credentials, optionally disabling SSH on the host, and preserving hostd.log and shell.log for incident investigation.
Categories
- Endpoint
- On-Premise
- Infrastructure
Data Sources
- Logon Session
ATT&CK Techniques
- T1021
- T1021.004
Created: 2026-09-30