
Summary
This rule detects when an ESXi (VMware vSphere) account is granted the Administrator role on a host. The Administrator role provides full control over the host, including firewall, SSH, accounts, and every virtual machine, and such a grant can persist beyond the initiating session, enabling a persistence path for an attacker. Detection relies on vSphere logs collected via the Elastic vSphere integration (logs-vsphere.log*, data_stream.dataset: vsphere.log) and inspects message content for permission changes to Administrator. It covers both shell-based and hostd-based forms, including messages that indicate system permission changes (for example, --role Admin or --role=Admin) and events such as Permission created for <name> with role is Administrator. The rule therefore flags an account granted Admin when the account is not part of the known, approved set. The detection uses a KQL query on data_stream.dataset:vsphere.log with event.module:vsphere and specific message patterns to identify Admin-role assignments. MITRE ATT&CK mapping links this to T1098 (Account Manipulation) under the Persistence tactic. The rule has a risk_score of 73 and severity set to high, appropriate for production use. Setup requires the Elastic vSphere integration. For triage, parse the account name from the message, compare it against known ESXi accounts (root, dcui, vpxuser, and approved operators), and look for preceding account creation events or esxcli system account additions. Confirm whether the account was used for SSH or subsequent esxcli commands. If the account appears unknown or unexpected, remediate by unsetting the permission and removing the account, rotate any exposed credentials, and hunt for the same account ID on other hosts. False positives may occur during approved provisioning; correlate with identity tickets to validate legitimacy.
Categories
- Infrastructure
Data Sources
- Application Log
- File
ATT&CK Techniques
- T1098
Created: 2026-09-30