Skip to content

Advanced Settings

Evidence: Advanced Settings
Description: ESXi Advanced Settings
Category: System
Platform: esxi
Short Name: advsettings
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

ESXi advanced settings provide granular control over hypervisor behavior, including security policies, resource allocation, logging verbosity, and feature toggles. These settings can be weaponized by attackers to weaken security, disable logging, or modify system behavior for persistence.

This collector gathers structured data about advanced settings.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector parses advanced system settings, extracting configuration keys, current values, default values, and setting descriptions from the ESXi advanced options database.

Advanced settings analysis reveals security weakening modifications, identifies disabled security features, detects altered logging configurations that hide attacker activity, and exposes non-standard settings that may indicate compromise. Comparing against security baselines highlights suspicious deviations.