
Summary
This rule detects when an ESXi host’s remote syslog destination (loghost) is cleared using a command such as --reset=loghost or --reset loghost. Clearing the loghost breaks the external retention/collection of host logs, potentially masking attacker activity and evading monitoring. The rule triggers when the Elastic vSphere logs contain a syslog reconfiguration event indicating a reset of the loghost. It decodes obfuscated lines that reference the exact esxcli command, and guides responders to verify the current loghost configuration, correlate with other activity, and restore logging if unauthorized. The rule is aligned with Defense Evasion, specifically T1562 (Impair Defenses) and its subtechnique T1562.001 (Disable or Modify Tools). With a high severity and risk score of 73, it emphasizes timely triage, remediation steps, and investigation guidance. It relies on the vSphere integration data (logs-vsphere.log) and is operational within a near real-time window (from: now-9m).
Categories
- Infrastructure
- Endpoint
Data Sources
- File
- Command
ATT&CK Techniques
- T1562
- T1562.001
Created: 2026-09-30