LoFP LoFP / administrators sometimes force a vendor vib during a documented recovery or upgrade when the acceptance level would otherwise reject it. confirm the vib name against the change ticket.

Techniques

Sample rules

ESXi Attempt to Force Install a VMware VIB Package

Description

Detects an attempt to install a VMware VIB with --force. A VIB is how ESXi adds drivers and host software, and signature checks normally block an unsigned package. --force skips that validation, so an untrusted package can be written onto the hypervisor and affect every virtual machine it runs.

Detection logic

data_stream.dataset:vsphere.log and event.module:vsphere and message:("vib install" and ("--force" or "-f" or "--no-sig-check"))