ESXi ExecInstalledOnly Protection Disabled
Description
Detects ESXi ExecInstalledOnly protection being turned off. The setting limits execution to binaries that were
installed by a VIB and have not been modified. When it is set to false, the host can run files from paths such
as /tmp that were never part of the system image.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:(execInstalledOnly and ("-i 0" or "-v 0" or FALSE))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Some recovery and lab images leave ExecInstalledOnly off, and an approved change can disable it while a custom VIB is installed. Confirm the setting is restored to TRUE afterward.
Analyst notes
Investigating ESXi ExecInstalledOnly Protection Disabled
ExecInstalledOnly limits execution to binaries that were installed by a VIB and have not been modified. Turning it off lets a later payload run from a path such as /tmp.
Possible investigation steps
- Read message for execInstalledOnly set to FALSE, or /User/ExecInstalledOnly set with -i 0.
- On the host, run esxcli system settings kernel list -o execInstalledOnly and compare Configured with Runtime.
- Look for a following vib install with --force, a chmod that adds execute permission, or a file launched from /tmp.
False positive analysis
A documented install of an unsigned vendor VIB can disable the setting for the duration of the change. The setting should be TRUE when the work is finished.
Response and remediation
- If the change was not approved, set the control back on: esxcli system settings kernel set -s execInstalledOnly -v TRUE.
- Review VIBs installed in the same session with esxcli software vib list.
- Preserve shell.log before rotating credentials.