
Summary
Detects when ESXi lockdown mode is disabled on an ESXi host. The rule relies on ESXi host logs gathered via the Elastic vSphere integration (data_stream.dataset: vsphere.log) and flags messages containing esx.audit.lockdownmode.disabled or lockdown_mode_exit. Disabling lockdown mode removes remote access restrictions, allowing direct administrator access via SSH or the API, which attackers could abuse. The rule is implemented as a Custom Query (KQL) against the vSphere logs, with event.module: vsphere and message patterns matching the lockdown mode change. MITRE ATT&CK mapping: T1562.001 Disable or Modify Tools (Defense Evasion, TA0005). The rule includes triage guidance such as inspecting the hostd user field for DCUI or other users, verifying lockdown state via vim-cmd -U dcui vimsvc/auth/lockdown_is_enabled, and checking for new accounts, Admin role grants, or root password changes within the same session. It also provides remediation steps to re-enable lockdown mode (DCUI or vim-cmd -U dcui vimsvc/auth/lockdown_mode_enter), review associated account changes, and preserve hostd.log before rotating credentials. False positives may occur during documented maintenance windows where lockdown mode is temporarily disabled, so changes should be ticketed and lockdown restored afterward. Setup notes specify that the rule requires ESXi host logs collected by the Elastic vSphere integration. Overall, the rule is a high-severity detection aimed at preventing unintended exposure of the ESXi management surface.
Categories
- Infrastructure
- On-Premise
- Endpoint
Data Sources
- Application Log
ATT&CK Techniques
- T1562
- T1562.001
Created: 2026-09-30