Skip to content
English
  • There are no suggestions because the search field is empty.

Security checks in the Ransomware Vulnerability Management Packs

Reference of every security check in the V70, V80 and V90 Ransomware Vulnerability packs, with target and default state.

Applies to: OpsLogix VMware Management Pack (all versions) with the Ransomware Vulnerability Management Packs V70, V80 and V90 · SCOM 2019, 2022, 2025 · vCenter 7.0, 8.0, 9.0
Last updated: October 2026 · Reading time: 6 minutes

The Ransomware Vulnerability Management Packs check your ESXi hosts, virtual machines and switches against the VMware security configuration guide for your vSphere version. This article lists every check in each pack, its target, and whether it is on by default. For setup steps, see Monitor vSphere for ransomware vulnerabilities.

Which packs are shipped

The release contains three versions. Each version has a monitoring pack and a Groups pack. You find them in the folder Management Packs\Ransomware Vulnerability Monitoring.

PackForBased on
V70vSphere 7VMware vSphere Security Configuration Guide 7
V80vSphere 8VMware security configuration recommendations for vSphere 8
V90vSphere 9VMware Cloud Foundation 9.0 Security Configuration Guide

Import the pack that matches your vSphere version.

How the checks work

  • Interval: every check runs every 6 hours (21,600 seconds).
  • Health state: Compliant is Healthy. Non Compliant is Critical. Any other result is Warning. The monitors roll up to the Security health of the object.
  • Alerts: raised from Warning and closed automatically when the setting is compliant again.
  • Host and switch checks are on by default.
  • Virtual machine checks are off by default. A large environment has many VMs, so you turn them on only for the VMs you want to check in detail.
  • Overall monitors: each pack has three overall monitors, one each for ESXi hosts, virtual machines and distributed virtual switches. They are on by default. An overall monitor turns Critical when any check for that object is Non Compliant, and the alert lists the failing checks with their current values. The virtual machine overall monitor evaluates all VM checks, even while the individual VM monitors are off.

Number of checks per pack

PackESXi host (on)Distributed virtual switch (on)Virtual machine (off)Overall monitors (on)
V70263113
V80263113
V90233123

Turn on the virtual machine checks

Each Groups pack contains a group named VMware V<version> VMs with Full Ransomware Vulnerability Check Enabled. It also contains overrides that set Enabled = True on every VM check for the members of that group.

  • V70: the Groups pack is unsealed. Add the VMs you want to check to the group.
  • V80 and V90: the Groups packs are sealed, so you can't edit the group membership. The group stays empty. Use this workaround instead:
    1. Create your own group in an unsealed management pack and add the VMs you want to check.
    2. For each virtual machine check in the table below, create an override for your group and set Enabled to True.

Display names in the console

In the SCOM console every check starts with "ESX V<version> Ransomware Vulnerability <object> Status", for example "ESX V90 Ransomware Vulnerability Host Status". The tables below leave that prefix out. Notes:

  • In V70 and V80 the console shows question marks instead of quotes in the three switch checks.
  • In V70 and V80 the copy check and the paste check have the same display name. The tables add "(copy)" and "(paste)" to tell them apart.
  • The overall monitors are named "ESX V<version> Ransomware Vulnerability Host Overall Status", "... VirtualMachine Overall Status" and "... DistributedVirtualSwitch Overall Status".

V70 checks (vSphere 7)

Check (display name)TargetOn by default
Ensure that the "Forged Transmits" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Ensure that the "MAC Address Changes" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Ensure that the "Promiscuous Mode" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Automatically unlock a locked account after a specific amount of time.ESXi hostYes
Set the count of maximum failed login attempts before the account is locked out.ESXi hostYes
Do not permit password reuse.ESXi hostYes
Establish a policy for password complexity.ESXi hostYes
Warning for potential hyperthreading security vulnerability is suppressed.ESXi hostYes
Set a timeout to automatically terminate idle DCUI sessions.ESXi hostYes
Configure or disable CIM.ESXi hostYes
Disable Managed Object Browser (MOB).ESXi hostYes
Configure or disable SLP.ESXi hostYes
Configure or disable SNMP.ESXi hostYes
Disable SSH.ESXi hostYes
Set DCUI.Access to allow trusted users to override lockdown mode.ESXi hostYes
Enable normal lockdown mode to restrict access to ESXi.ESXi hostYes
Set the logging informational level.ESXi hostYes
Configure persistent logging.ESXi hostYes
Configure remote logging.ESXi hostYes
Block guest OS BPDU transmissions.ESXi hostYes
Audit use of dvfilter network APIs.ESXi hostYes
Disable ESXi Shell.ESXi hostYes
Set a timeout to automatically terminate idle ESXi Shell and SSH sessions.ESXi hostYes
Set a timeout to limit how long the ESXi Shell and SSH services are allowed to run.ESXi hostYes
Warning for support and troubleshooting interfaces is suppressed.ESXi hostYes
Configure NTP or PTP.ESXi hostYes
Ensure that deprecated SSL/TLS protocols are disabled.ESXi hostYes
Restrict transparent page sharing to VMs configured with sched.mem.pshare.salt.ESXi hostYes
Only run binaries delivered via VIB.ESXi hostYes
Explicitly disable copy/paste operations. (copy)Virtual machineNo
Explicitly disable copy/paste operations. (paste)Virtual machineNo
Disable virtual disk shrinking.Virtual machineNo
Disable virtual disk wiping.Virtual machineNo
Disable 3D features if not needed.Virtual machineNo
Limit the number of console connections.Virtual machineNo
Limit informational messages from the VM to the VMX file.Virtual machineNo
Limit the number of retained VM diagnostic logs.Virtual machineNo
Limit the size of VM diagnostic logs.Virtual machineNo
Do not send host information to guests.Virtual machineNo
Check for enablement of salted VMs that are sharing memory pagesVirtual machineNo

V80 checks (vSphere 8)

Check (display name)TargetOn by default
Ensure that the "MAC Address Changes" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Ensure that the "Promiscuous Mode" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Ensure that the "Forged Transmits" policy is set to reject on both the vSphere Standard Switch and on its port groups.Distributed virtual switchYes
Automatically unlock a locked account after a specific amount of time.ESXi hostYes
Set the count of maximum failed login attempts before the account is locked out.ESXi hostYes
Do not permit password reuse.ESXi hostYes
Establish a policy for password complexity.ESXi hostYes
Warning for potential hyperthreading security vulnerability is suppressed.ESXi hostYes
Set a timeout to automatically terminate idle DCUI sessions.ESXi hostYes
Configure or disable CIM.ESXi hostYes
Disable Managed Object Browser (MOB).ESXi hostYes
Configure or disable SLP.ESXi hostYes
Configure or disable SNMP.ESXi hostYes
Disable SSH.ESXi hostYes
Set DCUI.Access to allow trusted users to override lockdown mode.ESXi hostYes
Enable normal lockdown mode to restrict access to ESXi.ESXi hostYes
Set the logging informational level.ESXi hostYes
Configure persistent logging.ESXi hostYes
Configure remote logging.ESXi hostYes
Block guest OS BPDU transmissions.ESXi hostYes
Audit use of dvfilter network APIs.ESXi hostYes
Disable ESXi Shell.ESXi hostYes
Set a timeout to automatically terminate idle ESXi Shell and SSH sessions.ESXi hostYes
Set a timeout to limit how long the ESXi Shell and SSH services are allowed to run.ESXi hostYes
Warning for support and troubleshooting interfaces is suppressed.ESXi hostYes
Configure NTP or PTP.ESXi hostYes
Ensure that deprecated SSL/TLS protocols are disabled.ESXi hostYes
Restrict transparent page sharing to VMs configured with sched.mem.pshare.salt.ESXi hostYes
Only run binaries delivered via VIB.ESXi hostYes
Explicitly disable copy/paste operations. (copy)Virtual machineNo
Explicitly disable copy/paste operations. (paste)Virtual machineNo
Disable virtual disk shrinking.Virtual machineNo
Disable virtual disk wiping.Virtual machineNo
Disable 3D features if not needed.Virtual machineNo
Limit the number of console connections.Virtual machineNo
Limit informational messages from the VM to the VMX file.Virtual machineNo
Limit the number of retained VM diagnostic logs.Virtual machineNo
Limit the size of VM diagnostic logs.Virtual machineNo
Do not send host information to guests.Virtual machineNo
Check for enablement of salted VMs that are sharing memory pagesVirtual machineNo

V90 checks (vSphere 9, VCF 9.0)

Check (display name)TargetOn by default
All standard switches and their port groups must be configured to reject forged transmits.Distributed virtual switchYes
All standard switches and their port groups must be configured to reject guest MAC address changes.Distributed virtual switchYes
All standard switches and their port groups must be configured to reject guest promiscuous mode requests.Distributed virtual switchYes
The ESX host must enforce an unlock timeout of 15 minutes.ESXi hostYes
The ESX host must enforce the limit of five consecutive invalid logon attempts by a user.ESXi hostYes
The ESX host must enforce password history for users.ESXi hostYes
The ESX host must not suppress warnings about unmitigated hyperthreading vulnerabilities.ESXi hostYes
Set a timeout to automatically terminate idle DCUI sessions on the ESX host.ESXi hostYes
The ESX Managed Object Browser (MOB) should be deactivated.ESXi hostYes
The ESX shell should be deactivated.ESXi hostYes
The ESX host must have an accurate DCUI.Access list.ESXi hostYes
The ESX host must enable lockdown mode.ESXi hostYes
Component must forward system and audit logs to a remote log collection point.ESXi hostYes
The ESX host must produce audit records containing information to establish what type of events occurred.ESXi hostYes
Configure a persistent log location for all locally stored logs on the ESX host.ESXi hostYes
Enable the Bridge Protocol Data Unit (BPDU) filter on the ESX host.ESXi hostYes
Use of the dvFilter network APIs must be restricted on the ESX host.ESXi hostYes
The ESX host must enforce password complexity by configuring a password quality policy.ESXi hostYes
Configure the inactivity timeout to automatically terminate idle ESX host shells.ESXi hostYes
Set a timeout to limit how long the ESX Shell and SSH services are allowed to run.ESXi hostYes
The ESX host must not suppress warnings that the ESX shell is enabled.ESXi hostYes
The component must disable SNMP version 1 and 2.ESXi hostYes
The component must deactivate SSH.ESXi hostYes
The component must synchronize its clock with organizational reference sources.ESXi hostYes
The ESX host must restrict inter-VM transparent page sharing to VMs configured with sched.mem.pshare.salt.ESXi hostYes
Only run binaries delivered via signed VIB.ESXi hostYes
Virtual machines must have console copy operations deactivated.Virtual machineNo
Virtual machines must have console paste operations deactivated.Virtual machineNo
Virtual machines must have virtual disk shrinking operations deactivated.Virtual machineNo
Virtual machines must have virtual disk wiping operations deactivated.Virtual machineNo
Virtual machines must have 3D graphics features deactivated when not required.Virtual machineNo
Virtual machines must limit console sharing.Virtual machineNo
Virtual machines must limit informational messages from the virtual machine to the VMX file.Virtual machineNo
Virtual machines must limit the number of retained diagnostic logs.Virtual machineNo
Virtual machines must limit the size of diagnostic logs.Virtual machineNo
Virtual machines must not be able to obtain host information from the hypervisor.Virtual machineNo
Virtual machines must restrict sharing of memory pages between VMs.Virtual machineNo
Virtual machines must be configured to lock when the last console connection is closed.Virtual machineNo

See also