
Summary
Detects creation of a local ESXi account by analyzing ESXi host logs collected via the Elastic vSphere integration. The rule flags events where the hostd/Host Client or API creates a local account (esxcli system account add), resulting in a new login that has no rights until a role is assigned—constituting the first step toward persistence on the host. The detection relies on the vsphere.log data stream and searches for patterns such as messages indicating creation (e.g., Account <name> was created) or the esxcli system account add invocation. It maps to MITRE ATT&CK techniques T1136 (Create Account) and T1136.001 (Local Account) under the Persistence tactic TA0003. The rule has a medium severity with a risk score of 47. False positives include documented onboarding or break-glass accounts; review should compare the account against an approved host account list and whether it was granted a privileged role. Investigation should verify the account name, identify the creator from the event, and check for subsequent permission changes (e.g., Admin role grants). Remediation involves removing unapproved accounts with esxcli system account remove --id <name> and preserving hostd.log and shell.log for auditing. Setup requires the Elastic vSphere integration to collect ESXi host logs. References include ESXi logging and security analyses.
Categories
- Infrastructure
Data Sources
- Application Log
- File
ATT&CK Techniques
- T1136
- T1136.001
Created: 2026-09-30