LoFP LoFP / administrators disable lockdown mode for a documented maintenance window, then turn it back on. confirm the change ticket and that lockdown mode is enabled again afterward.

Techniques

Sample rules

ESXi Lockdown Mode Disabled

Description

Detects the disabling of ESXi lockdown mode, a critical security feature that restricts remote access to ESXi hosts. When lockdown mode is disabled, remote users can directly access and modify ESXi host configurations using the root login. When enabled, the ESXi host is accessible only through the local console or vCenter Server.

Detection logic

data_stream.dataset:vsphere.log and event.module:vsphere and message:(esx.audit.lockdownmode.disabled or lockdown_mode_exit)