ESXi File Made Executable with chmod

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects chmod making a file executable on an ESXi host, including `+x` and numeric modes such as `755` and `777`. The host will not run a file until the execute bit is set. Making a file under `/tmp` executable is the step that lets a later command launch it against the datastore.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: Defense EvasionRule Type: Custom Query (KQL)Platform: VMware ESXiThreat: RansomwareLanguage: kuery
Severity
medium
Risk Score
47
MITRE ATT&CK™

Defense Evasion (TA0005)(external, opens in a new tab or window)

False Positive Examples
Administrators mark a maintenance or support script executable during a change window. Confirm the path, the account, and whether the same session then executes a file from `/tmp` or enumerates virtual disks.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-vsphere.log-*
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:vsphere.log and event.module:vsphere and message:(chmod and ("+x" or 0511 or 0555 or 0700 or 0711 or 0750 or 0755 or 0775 or 0777 or 111 or 1777 or 4755 or 511 or 555 or 700 or 711 or 750 or 755 or 775 or 777 or "a+x" or "g+x" or "o+x" or "u+x"))

Install detection rules in Elastic Security

Detect ESXi File Made Executable with chmod in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).