ESXi File Made Executable with chmod
Description
Detects chmod making a file executable on an ESXi host, including +x and numeric modes such as 755 and 777.
The host will not run a file until the execute bit is set. Making a file under /tmp executable is the step that
lets a later command launch it against the datastore.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:(chmod and ("+x" or 0511 or 0555 or 0700 or 0711 or 0750 or 0755 or 0775 or 0777 or 111 or 1777 or 4755 or 511 or 555 or 700 or 711 or 750 or 755 or 775 or 777 or "a+x" or "g+x" or "o+x" or "u+x"))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators mark a maintenance or support script executable during a change window. Confirm the path, the account, and whether the same session then executes a file from `/tmp` or enumerates virtual disks.
Analyst notes
Investigating ESXi File Made Executable with chmod
chmod +x, chmod a+x, and numeric modes such as 777 and 755 add the execute bit. On ESXi this is the step that turns a file dropped in /tmp into a runnable payload. Modes that do not grant execute, such as 644, are not included.
Possible investigation steps
- Read the full command in message, including the target path.
- Check the same session for a copy into /tmp, a following execution of that path, VM process kills, or a search for vmdk files.
- Confirm with the virtualization owner whether that file was part of an approved script.
False positive analysis
Support workflows sometimes chmod a known script. A chmod of an unknown file under /tmp, followed by execution, is the staging pattern.
Response and remediation
- If the file was not approved, remove it and end the shell session.
- Preserve shell.log and review commands issued after the chmod.
- If the path was executed, isolate the host and rotate credentials used in that session.