heroui logo

ESXi Attempt to Force Install a VMware VIB Package

Elastic Detection Rules

View Source
Summary
This rule flags an ESXi host attempting to force-install a VMware VIB package by monitoring vSphere logs for esxcli vib install invocations that include force-related flags. A VIB is how ESXi installs drivers and host software; forceful installation bypasses signature/acceptance checks, enabling an unsigned package to be written to the hypervisor and potentially affect all running VMs. The detection targets data_stream.dataset: vsphere.log with event.module: vsphere and message patterns: 'vib install' combined with --force, -f, or --no-sig-check. Investigation should verify the VIB path (look for /tmp), compare installed VIBs against the approved image (esxcli vib list), and check session context (ExecInstalledOnly, SSH status). False positives include approved maintenance windows where admins intentionally force-install vendor VIBs; confirm the VIB name aligns with the change ticket. Remediation for unapproved activity includes removing the VIB (esxcli software vib remove), inspecting /tmp artifacts, restoring ExecInstalledOnly to TRUE, and preserving shell logs. MITRE ATT&CK mapping: Defense Evasion (TA0005), Subvert Trust Controls (T1553), Code Signing Policy Modification (T1553.006).
Categories
  • Infrastructure
Data Sources
  • Application Log
ATT&CK Techniques
  • T1553
  • T1553.006
Created: 2026-09-30