Security checks in the Ransomware Vulnerability Management Packs
Reference of every security check in the V70, V80 and V90 Ransomware Vulnerability packs, with target and default state.
Applies to: OpsLogix VMware Management Pack (all versions) with the Ransomware Vulnerability Management Packs V70, V80 and V90 · SCOM 2019, 2022, 2025 · vCenter 7.0, 8.0, 9.0
Last updated: October 2026 · Reading time: 6 minutes
The Ransomware Vulnerability Management Packs check your ESXi hosts, virtual machines and switches against the VMware security configuration guide for your vSphere version. This article lists every check in each pack, its target, and whether it is on by default. For setup steps, see Monitor vSphere for ransomware vulnerabilities.
Which packs are shipped
The release contains three versions. Each version has a monitoring pack and a Groups pack. You find them in the folder Management Packs\Ransomware Vulnerability Monitoring.
| Pack | For | Based on |
| V70 | vSphere 7 | VMware vSphere Security Configuration Guide 7 |
| V80 | vSphere 8 | VMware security configuration recommendations for vSphere 8 |
| V90 | vSphere 9 | VMware Cloud Foundation 9.0 Security Configuration Guide |
Import the pack that matches your vSphere version.
How the checks work
- Interval: every check runs every 6 hours (21,600 seconds).
- Health state: Compliant is Healthy. Non Compliant is Critical. Any other result is Warning. The monitors roll up to the Security health of the object.
- Alerts: raised from Warning and closed automatically when the setting is compliant again.
- Host and switch checks are on by default.
- Virtual machine checks are off by default. A large environment has many VMs, so you turn them on only for the VMs you want to check in detail.
- Overall monitors: each pack has three overall monitors, one each for ESXi hosts, virtual machines and distributed virtual switches. They are on by default. An overall monitor turns Critical when any check for that object is Non Compliant, and the alert lists the failing checks with their current values. The virtual machine overall monitor evaluates all VM checks, even while the individual VM monitors are off.
Number of checks per pack
| Pack | ESXi host (on) | Distributed virtual switch (on) | Virtual machine (off) | Overall monitors (on) |
| V70 | 26 | 3 | 11 | 3 |
| V80 | 26 | 3 | 11 | 3 |
| V90 | 23 | 3 | 12 | 3 |
Turn on the virtual machine checks
Each Groups pack contains a group named VMware V<version> VMs with Full Ransomware Vulnerability Check Enabled. It also contains overrides that set Enabled = True on every VM check for the members of that group.
- V70: the Groups pack is unsealed. Add the VMs you want to check to the group.
- V80 and V90: the Groups packs are sealed, so you can't edit the group membership. The group stays empty. Use this workaround instead:
- Create your own group in an unsealed management pack and add the VMs you want to check.
- For each virtual machine check in the table below, create an override for your group and set Enabled to True.
Display names in the console
In the SCOM console every check starts with "ESX V<version> Ransomware Vulnerability <object> Status", for example "ESX V90 Ransomware Vulnerability Host Status". The tables below leave that prefix out. Notes:
- In V70 and V80 the console shows question marks instead of quotes in the three switch checks.
- In V70 and V80 the copy check and the paste check have the same display name. The tables add "(copy)" and "(paste)" to tell them apart.
- The overall monitors are named "ESX V<version> Ransomware Vulnerability Host Overall Status", "... VirtualMachine Overall Status" and "... DistributedVirtualSwitch Overall Status".
V70 checks (vSphere 7)
| Check (display name) | Target | On by default |
| Ensure that the "Forged Transmits" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Ensure that the "MAC Address Changes" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Ensure that the "Promiscuous Mode" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Automatically unlock a locked account after a specific amount of time. | ESXi host | Yes |
| Set the count of maximum failed login attempts before the account is locked out. | ESXi host | Yes |
| Do not permit password reuse. | ESXi host | Yes |
| Establish a policy for password complexity. | ESXi host | Yes |
| Warning for potential hyperthreading security vulnerability is suppressed. | ESXi host | Yes |
| Set a timeout to automatically terminate idle DCUI sessions. | ESXi host | Yes |
| Configure or disable CIM. | ESXi host | Yes |
| Disable Managed Object Browser (MOB). | ESXi host | Yes |
| Configure or disable SLP. | ESXi host | Yes |
| Configure or disable SNMP. | ESXi host | Yes |
| Disable SSH. | ESXi host | Yes |
| Set DCUI.Access to allow trusted users to override lockdown mode. | ESXi host | Yes |
| Enable normal lockdown mode to restrict access to ESXi. | ESXi host | Yes |
| Set the logging informational level. | ESXi host | Yes |
| Configure persistent logging. | ESXi host | Yes |
| Configure remote logging. | ESXi host | Yes |
| Block guest OS BPDU transmissions. | ESXi host | Yes |
| Audit use of dvfilter network APIs. | ESXi host | Yes |
| Disable ESXi Shell. | ESXi host | Yes |
| Set a timeout to automatically terminate idle ESXi Shell and SSH sessions. | ESXi host | Yes |
| Set a timeout to limit how long the ESXi Shell and SSH services are allowed to run. | ESXi host | Yes |
| Warning for support and troubleshooting interfaces is suppressed. | ESXi host | Yes |
| Configure NTP or PTP. | ESXi host | Yes |
| Ensure that deprecated SSL/TLS protocols are disabled. | ESXi host | Yes |
| Restrict transparent page sharing to VMs configured with sched.mem.pshare.salt. | ESXi host | Yes |
| Only run binaries delivered via VIB. | ESXi host | Yes |
| Explicitly disable copy/paste operations. (copy) | Virtual machine | No |
| Explicitly disable copy/paste operations. (paste) | Virtual machine | No |
| Disable virtual disk shrinking. | Virtual machine | No |
| Disable virtual disk wiping. | Virtual machine | No |
| Disable 3D features if not needed. | Virtual machine | No |
| Limit the number of console connections. | Virtual machine | No |
| Limit informational messages from the VM to the VMX file. | Virtual machine | No |
| Limit the number of retained VM diagnostic logs. | Virtual machine | No |
| Limit the size of VM diagnostic logs. | Virtual machine | No |
| Do not send host information to guests. | Virtual machine | No |
| Check for enablement of salted VMs that are sharing memory pages | Virtual machine | No |
V80 checks (vSphere 8)
| Check (display name) | Target | On by default |
| Ensure that the "MAC Address Changes" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Ensure that the "Promiscuous Mode" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Ensure that the "Forged Transmits" policy is set to reject on both the vSphere Standard Switch and on its port groups. | Distributed virtual switch | Yes |
| Automatically unlock a locked account after a specific amount of time. | ESXi host | Yes |
| Set the count of maximum failed login attempts before the account is locked out. | ESXi host | Yes |
| Do not permit password reuse. | ESXi host | Yes |
| Establish a policy for password complexity. | ESXi host | Yes |
| Warning for potential hyperthreading security vulnerability is suppressed. | ESXi host | Yes |
| Set a timeout to automatically terminate idle DCUI sessions. | ESXi host | Yes |
| Configure or disable CIM. | ESXi host | Yes |
| Disable Managed Object Browser (MOB). | ESXi host | Yes |
| Configure or disable SLP. | ESXi host | Yes |
| Configure or disable SNMP. | ESXi host | Yes |
| Disable SSH. | ESXi host | Yes |
| Set DCUI.Access to allow trusted users to override lockdown mode. | ESXi host | Yes |
| Enable normal lockdown mode to restrict access to ESXi. | ESXi host | Yes |
| Set the logging informational level. | ESXi host | Yes |
| Configure persistent logging. | ESXi host | Yes |
| Configure remote logging. | ESXi host | Yes |
| Block guest OS BPDU transmissions. | ESXi host | Yes |
| Audit use of dvfilter network APIs. | ESXi host | Yes |
| Disable ESXi Shell. | ESXi host | Yes |
| Set a timeout to automatically terminate idle ESXi Shell and SSH sessions. | ESXi host | Yes |
| Set a timeout to limit how long the ESXi Shell and SSH services are allowed to run. | ESXi host | Yes |
| Warning for support and troubleshooting interfaces is suppressed. | ESXi host | Yes |
| Configure NTP or PTP. | ESXi host | Yes |
| Ensure that deprecated SSL/TLS protocols are disabled. | ESXi host | Yes |
| Restrict transparent page sharing to VMs configured with sched.mem.pshare.salt. | ESXi host | Yes |
| Only run binaries delivered via VIB. | ESXi host | Yes |
| Explicitly disable copy/paste operations. (copy) | Virtual machine | No |
| Explicitly disable copy/paste operations. (paste) | Virtual machine | No |
| Disable virtual disk shrinking. | Virtual machine | No |
| Disable virtual disk wiping. | Virtual machine | No |
| Disable 3D features if not needed. | Virtual machine | No |
| Limit the number of console connections. | Virtual machine | No |
| Limit informational messages from the VM to the VMX file. | Virtual machine | No |
| Limit the number of retained VM diagnostic logs. | Virtual machine | No |
| Limit the size of VM diagnostic logs. | Virtual machine | No |
| Do not send host information to guests. | Virtual machine | No |
| Check for enablement of salted VMs that are sharing memory pages | Virtual machine | No |
V90 checks (vSphere 9, VCF 9.0)
| Check (display name) | Target | On by default |
| All standard switches and their port groups must be configured to reject forged transmits. | Distributed virtual switch | Yes |
| All standard switches and their port groups must be configured to reject guest MAC address changes. | Distributed virtual switch | Yes |
| All standard switches and their port groups must be configured to reject guest promiscuous mode requests. | Distributed virtual switch | Yes |
| The ESX host must enforce an unlock timeout of 15 minutes. | ESXi host | Yes |
| The ESX host must enforce the limit of five consecutive invalid logon attempts by a user. | ESXi host | Yes |
| The ESX host must enforce password history for users. | ESXi host | Yes |
| The ESX host must not suppress warnings about unmitigated hyperthreading vulnerabilities. | ESXi host | Yes |
| Set a timeout to automatically terminate idle DCUI sessions on the ESX host. | ESXi host | Yes |
| The ESX Managed Object Browser (MOB) should be deactivated. | ESXi host | Yes |
| The ESX shell should be deactivated. | ESXi host | Yes |
| The ESX host must have an accurate DCUI.Access list. | ESXi host | Yes |
| The ESX host must enable lockdown mode. | ESXi host | Yes |
| Component must forward system and audit logs to a remote log collection point. | ESXi host | Yes |
| The ESX host must produce audit records containing information to establish what type of events occurred. | ESXi host | Yes |
| Configure a persistent log location for all locally stored logs on the ESX host. | ESXi host | Yes |
| Enable the Bridge Protocol Data Unit (BPDU) filter on the ESX host. | ESXi host | Yes |
| Use of the dvFilter network APIs must be restricted on the ESX host. | ESXi host | Yes |
| The ESX host must enforce password complexity by configuring a password quality policy. | ESXi host | Yes |
| Configure the inactivity timeout to automatically terminate idle ESX host shells. | ESXi host | Yes |
| Set a timeout to limit how long the ESX Shell and SSH services are allowed to run. | ESXi host | Yes |
| The ESX host must not suppress warnings that the ESX shell is enabled. | ESXi host | Yes |
| The component must disable SNMP version 1 and 2. | ESXi host | Yes |
| The component must deactivate SSH. | ESXi host | Yes |
| The component must synchronize its clock with organizational reference sources. | ESXi host | Yes |
| The ESX host must restrict inter-VM transparent page sharing to VMs configured with sched.mem.pshare.salt. | ESXi host | Yes |
| Only run binaries delivered via signed VIB. | ESXi host | Yes |
| Virtual machines must have console copy operations deactivated. | Virtual machine | No |
| Virtual machines must have console paste operations deactivated. | Virtual machine | No |
| Virtual machines must have virtual disk shrinking operations deactivated. | Virtual machine | No |
| Virtual machines must have virtual disk wiping operations deactivated. | Virtual machine | No |
| Virtual machines must have 3D graphics features deactivated when not required. | Virtual machine | No |
| Virtual machines must limit console sharing. | Virtual machine | No |
| Virtual machines must limit informational messages from the virtual machine to the VMX file. | Virtual machine | No |
| Virtual machines must limit the number of retained diagnostic logs. | Virtual machine | No |
| Virtual machines must limit the size of diagnostic logs. | Virtual machine | No |
| Virtual machines must not be able to obtain host information from the hypervisor. | Virtual machine | No |
| Virtual machines must restrict sharing of memory pages between VMs. | Virtual machine | No |
| Virtual machines must be configured to lock when the last console connection is closed. | Virtual machine | No |