ESXi Account Granted Admin Role
Description
Detects an ESXi account being granted the Administrator role. Administrator is full control of the host, including the firewall, SSH, accounts, and every virtual machine. Granting it to another account keeps that access after the original session ends.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("system permission set" and ("--role Admin" or "--role=Admin") or "Permission created" and "role is Administrator")
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- New virtualization administrators and service accounts are granted Admin during approved account provisioning. Confirm the account name against the identity ticket.
Analyst notes
Investigating ESXi Account Granted Admin Role
Admin on a standalone ESXi host can change the firewall, syslog, SSH, and every virtual machine. Granting that role to an unexpected account is a persistence path that survives the interactive session.
Possible investigation steps
- Read the account name in message. The shell form uses --id. The hostd form is Permission created for .
- Compare that name with known ESXi accounts (root, dcui, vpxuser, and approved operators).
- Look for a preceding Account was created or esxcli system account add for the same id.
- Check whether that account was used for SSH or further esxcli commands.
False positive analysis
Joiner automation and break-glass account setup grant Admin on purpose. The account id should match a ticket.
Response and remediation
- If the account is unknown, remove the permission and the account: esxcli system permission unset and esxcli system account remove.
- Rotate credentials that were exposed in the same session.
- Hunt other hosts for the same account id.