Skip to content

Account Info

Evidence: Account Info
Description: ESXi Account Info
Category: System
Platform: esxi
Short Name: accinfo
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Local ESXi accounts define administrative and service access to the hypervisor. Enumerating them supports auditing and detection of unauthorized users.

This collector gathers structured data about account info.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses esxcli system account list output captured in a text file to enumerate local user accounts and descriptions.

Account inventories enable validation against policy, detection of rogue accounts, and correlation with authentication events.