ESXi Local Account Created
Description
Detects creation of a local ESXi account. A new account is a separate login that remains after the session that created it. It has no rights until a role is assigned, and it is the first step toward a persistent login on the host.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("esxcli system account add" or Account and "was created")
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Administrators create local accounts during onboarding or break-glass setup. Confirm the account name and whether it was then granted the Admin role.
Analyst notes
Investigating ESXi Local Account Created
Hostd records Account was created on host when an account is added from the Host Client or API. The shell records esxcli system account add. The new account has no role until a later permission change.
Possible investigation steps
- Read the account name in message and the user field on the hostd event, which is the account that created it.
- Look for a following esxcli system permission set or an Admin role grant for the same account.
- Compare the account with the approved list for that host.
False positive analysis
A documented joiner or break-glass account is commonly benign. An unknown account created by root over the Host Client, then granted Admin, deserves review.
Response and remediation
- If the account was not approved, remove it with esxcli system account remove --id .
- Preserve hostd.log and shell.log for the creating session.