Back to results

ESXi Root Password Accepted from Remote Host

Detects hostd accepting the ESXi root password from a remote address. A successful remote root login opens the Host Client or the API with full control of the host. Local sessions from 127.0.0.1 are left out of the rule.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source category
event_index

Known benign triggers

  • Administrators sign in to the Host Client or the API as root from a jump host during maintenance. Confirm the source address is a known workstation and that the session does not continue into SSH enablement, file copies to `/tmp`, or virtual machine shutdowns.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice