ESXi Lockdown Mode Disabled
Description
Detects the disabling of ESXi lockdown mode, a critical security feature that restricts remote access to ESXi hosts. When lockdown mode is disabled, remote users can directly access and modify ESXi host configurations using the root login. When enabled, the ESXi host is accessible only through the local console or vCenter Server.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:(esx.audit.lockdownmode.disabled or lockdown_mode_exit)
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators disable lockdown mode for a documented maintenance window, then turn it back on. Confirm the change ticket and that lockdown mode is enabled again afterward.
Analyst notes
Investigating ESXi Lockdown Mode Disabled
Lockdown mode limits remote administration of the host. Turning it off restores direct administrator access from SSH and the API.
Possible investigation steps
- Read message for esx.audit.lockdownmode.disabled or the shell command lockdown_mode_exit. A DCUI change records the audit id and does not record lockdown_mode_exit.
- Note the account in the hostd user field. A DCUI change shows user=dcui.
- On the host, run vim-cmd -U dcui vimsvc/auth/lockdown_is_enabled and confirm whether it is still off.
- Check the same session for new accounts, an Admin role grant, or a root password change.
False positive analysis
A short maintenance window that disables lockdown mode and enables it again can be expected. The host should not be left with lockdown mode off.
Response and remediation
- If the change was not approved, enable lockdown mode again from the DCUI or with vim-cmd -U dcui vimsvc/auth/lockdown_mode_enter.
- Review accounts and permissions changed in the same session.
- Preserve hostd.log before rotating credentials.