ESXi Account Granted Admin Role

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects an ESXi account being granted the Administrator role. Administrator is full control of the host, including the firewall, SSH, accounts, and every virtual machine. Granting it to another account keeps that access after the original session ends.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: PersistenceRule Type: Custom Query (KQL)Platform: VMware ESXiLanguage: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Persistence (TA0003)(external, opens in a new tab or window)

False Positive Examples
New virtualization administrators and service accounts are granted Admin during approved account provisioning. Confirm the account name against the identity ticket.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-vsphere.log-*
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:vsphere.log and event.module:vsphere and message:("system permission set" and ("--role Admin" or "--role=Admin") or "Permission created" and "role is Administrator")

Install detection rules in Elastic Security

Detect ESXi Account Granted Admin Role in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).