LoFP LoFP / administrators sign in to the host client or the api as root from a jump host during maintenance. confirm the source address is a known workstation and that the session does not continue into ssh enablement, file copies to `/tmp`, or virtual machine shutdowns.

Techniques

Sample rules

ESXi Root Password Accepted from Remote Host

Description

Detects hostd accepting the ESXi root password from a remote address. A successful remote root login opens the Host Client or the API with full control of the host. Local sessions from 127.0.0.1 are left out of the rule.

Detection logic

data_stream.dataset:vsphere.log and event.module:vsphere and message:("Accepted password for user root" and not "from 127.0.0.1")