Techniques
Sample rules
ESXi Lockdown Mode Disabled
- source: elastic
- technicques:
- T1562
Description
Detects the disabling of ESXi lockdown mode, a critical security feature that restricts remote access to ESXi hosts. When lockdown mode is disabled, remote users can directly access and modify ESXi host configurations using the root login. When enabled, the ESXi host is accessible only through the local console or vCenter Server.
Detection logic
data_stream.dataset:vsphere.log and event.module:vsphere and message:(esx.audit.lockdownmode.disabled or lockdown_mode_exit)