ESXi SSH Session from vpxuser
Description
Identifies a successful SSH session opened by the privileged vpxuser account. vpxuser is a service account used by VMware vCenter Server to manage ESXi hosts. An SSH session from that account reaches the host shell directly, outside the vCenter management path, and is a sign the credential is being reused with malicious intent.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:("SSH session was opened for" and vpxuser)
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Rare troubleshooting can open an SSH session with vpxuser. Confirm the source address and that the session matches a change ticket. vCenter itself manages hosts through the API, not through SSH as vpxuser.
Analyst notes
Investigating ESXi SSH Session from vpxuser
Hostd records SSH session was opened for 'vpxuser@
' when that account gets a shell. vpxuser is created for vCenter and is not an interactive operator account.Possible investigation steps
- Read the address after vpxuser@ in message and compare it with the vCenter server.
- Review shell commands in the same session, especially copies to /tmp, vm process, and datastore paths.
- Check whether SSH was enabled on this host just before the session.
- Ask whether anyone used vpxuser for a documented console session.
False positive analysis
An approved break-glass SSH session with vpxuser should be rare and tied to a ticket. A session from an address that is not the vCenter server deserves review.
Response and remediation
- If the session was not approved, disable SSH and terminate the session.
- Rotate the vpxuser credential from vCenter and review other hosts for the same account.
- Preserve hostd.log and shell.log for the session.