ESXi Attempt to Force Install a VMware VIB Package
Description
Detects an attempt to install a VMware VIB with --force. A VIB is how ESXi adds drivers and host software,
and signature checks normally block an unsigned package. --force skips that validation, so an untrusted
package can be written onto the hypervisor and affect every virtual machine it runs.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("vib install" and ("--force" or "-f" or "--no-sig-check"))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.pathprocess.pid
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators sometimes force a vendor VIB during a documented recovery or upgrade when the acceptance level would otherwise reject it. Confirm the VIB name against the change ticket.
Analyst notes
Investigating ESXi Attempt to Force Install a VMware VIB Package
esxcli software vib install --force writes the package even when its signature or acceptance level would block it. The shell records the command in shell.log, including attempts that fail because the file is missing.
Possible investigation steps
- Read the VIB path in message (-v, -d, or --viburl). A path under /tmp is worth a closer look.
- On the host, run esxcli software vib list and compare new packages with the approved image.
- Check the same session for ExecInstalledOnly set to FALSE and SSH being enabled.
False positive analysis
A forced install of a known vendor VIB during an approved window can be expected. The package name should match the ticket.
Response and remediation
- If the package was not approved, remove it with esxcli software vib remove and review files left under /tmp.
- Set ExecInstalledOnly back to TRUE if it was turned off in the same session.
- Preserve shell.log before rotating credentials.