Skip to content

Permission Info

Evidence: Permission Info
Description: ESXi Permission Info
Category: System
Platform: esxi
Short Name: perminfo
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Permission information defines user and group access rights to ESXi resources, VMs, datastores, and management functions. Permission assignments control what actions users can perform and are frequently targeted for privilege escalation attacks or persistence establishment.

This collector gathers structured data about permission info.

FieldDescriptionExample
PrincipalPrincipalExample value
IsGroupIs GroupExample value
RoleNameRole NameExample value
RoleDescriptionRole DescriptionExample value

This collector parses permission assignments, extracting user/group identifiers, assigned roles, permission levels, resource targets (VMs, hosts, datastores), inheritance settings, and effective permissions for each access control entry.

Permission analysis reveals unauthorized privilege grants, identifies excessive permissions, detects role assignment anomalies, and traces access control modifications. Unexpected permission changes or overly broad grants indicate potential compromise or insider threat activity.