ESXi Multiple Logon Failures by User and Source

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects three or more failed ESXi logons for the same account from the same remote address within 10 minutes. Hostd records each failure from `pam_do_authenticate` with the login name and `rhost`. Repeated failures from one source are password guessing against that account and can lock it or come just before a successful login.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: Credential AccessRule Type: ES|QLPlatform: VMware ESXiLanguage: esql
Severity
medium
Risk Score
47
MITRE ATT&CK™

Credential Access (TA0006)(external, opens in a new tab or window)

False Positive Examples
An administrator who mistypes the root password in the Host Client a few times can reach three failures. Confirm the source address is a known workstation and that a successful login did not follow.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Integration Pack
Prebuilt Security Detection Rules
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
FROM logs-vsphere.log-* | WHERE data_stream.dataset == "vsphere.log" AND event.module == "vsphere" AND message LIKE "*pam_do_authenticate: error*" | GROK message "%{DATA}rhost=%{IP:source_ip}%{DATA}login:%{DATA:user}]%{GREEDYDATA}" | WHERE user IS NOT NULL AND source_ip IS NOT NULL | EVAL user.name = user, source.ip = source_ip | STATS Esql.failure_count = COUNT(*), Esql.first_seen = MIN(@timestamp), Esql.last_seen = MAX(@timestamp), Esql.message_values = VALUES(message) BY user.name, source.ip, host.ip | WHERE Esql.failure_count >= 3 | EVAL message = MV_FIRST(Esql.message_values) | KEEP message, user.name, source.ip, host.ip, Esql.failure_count, Esql.first_seen, Esql.last_seen, Esql.message_values

Install detection rules in Elastic Security

Detect ESXi Multiple Logon Failures by User and Source in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).