ESXi Root Password Accepted from Remote Host

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects hostd accepting the ESXi root password from a remote address. A successful remote root login opens the Host Client or the API with full control of the host. Local sessions from 127.0.0.1 are left out of the rule.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: Initial AccessRule Type: Custom Query (KQL)Platform: VMware ESXiThreat: RansomwareLanguage: kuery
Severity
medium
Risk Score
47
MITRE ATT&CK™

Initial Access (TA0001)(external, opens in a new tab or window)

False Positive Examples
Administrators sign in to the Host Client or the API as root from a jump host during maintenance. Confirm the source address is a known workstation and that the session does not continue into SSH enablement, file copies to `/tmp`, or virtual machine shutdowns.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-vsphere.log-*
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:vsphere.log and event.module:vsphere and message:("Accepted password for user root" and not "from 127.0.0.1")

Install detection rules in Elastic Security

Detect ESXi Root Password Accepted from Remote Host in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).