Back to results

ESXi Root Password Changed

Detects a change to the ESXi root password, the credential for SSH, the Host Client, and the API. Replacing it locks out the previous password and gives the new value full control of the host. Hostd records `Password…

Description

Detects a change to the ESXi root password, the credential for SSH, the Host Client, and the API. Replacing it locks out the previous password and gives the new value full control of the host. Hostd records `Password was changed for account root`. The shell records `esxcli system account set -i root`.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Log source category
event_index

Known benign triggers

  • Administrators rotate the root password during scheduled maintenance. Confirm the change ticket and that the new password was stored with the approved break-glass process.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice