ESXi SSH Session from vpxuser
Identifies a successful SSH session opened by the privileged vpxuser account. vpxuser is a service account used by VMware vCenter Server to manage ESXi hosts. An SSH session from that account reaches the host shell…
Description
Identifies a successful SSH session opened by the privileged vpxuser account. vpxuser is a service account used by VMware vCenter Server to manage ESXi hosts. An SSH session from that account reaches the host shell directly, outside the vCenter management path, and is a sign the credential is being reused with malicious intent.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
Known benign triggers
- Rare troubleshooting can open an SSH session with vpxuser. Confirm the source address and that the session matches a change ticket. vCenter itself manages hosts through the API, not through SSH as vpxuser.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| blogs.vmware.com/security/2022/10/esxi-targeting-ransomware-tactics-and-techniques-part-2.html | 25 |
| detect.fyi/vmware-esxi-logging-detection-opportunities-4fb56411ec21 | 25 |
| lolesxi-project.github.io/LOLESXi/# | 25 |
From the source
- At source
- Open at source
- Upstream identifier
- eb4de742-3183-55a9-942f-c3d3d93d806b
- Tagged by the source as
- Data Source: VMware vSphereDomain: EndpointPlatform: VMware ESXiResources: Investigation GuideRule Type: Custom Query (KQL)Tactic: Lateral MovementUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 2, 2026
- Version
- 1