ESXi SSH Session from vpxuser

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Identifies a successful SSH session opened by the privileged vpxuser account. vpxuser is a service account used by VMware vCenter Server to manage ESXi hosts. An SSH session from that account reaches the host shell directly, outside the vCenter management path, and is a sign the credential is being reused with malicious intent.
Tags
Domain: EndpointData Source: VMware vSphereUse Case: Threat DetectionTactic: Lateral MovementRule Type: Custom Query (KQL)Platform: VMware ESXiLanguage: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Lateral Movement (TA0008)(external, opens in a new tab or window)

False Positive Examples
Rare troubleshooting can open an SSH session with vpxuser. Confirm the source address and that the session matches a change ticket. vCenter itself manages hosts through the API, not through SSH as vpxuser.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-vsphere.log-*
Related Integrations

vsphere(external, opens in a new tab or window)

Query
text code block:
data_stream.dataset:vsphere.log and event.module:vsphere and message:("SSH session was opened for" and vpxuser)

Install detection rules in Elastic Security

Detect ESXi SSH Session from vpxuser in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).