Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004

Tactic: Defense Impairment

Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system activity such as process, network, file, and login events based on pre-configured rules.

Events covered

4 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
Linux-AuditdEvent ID 1200DAEMON_START
Linux-AuditdEvent ID 1201DAEMON_END
Linux-AuditdEvent ID 1202DAEMON_ABORT
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
sourcetype3eq 3auditd
type3eq 3daemon_abort, daemon_end, daemon_start
CommandLine1regex_match 1-D
Image1ends_with 1/auditctl

Top indicator values (6 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypeeq
auditd
358
CommandLineregex_match
-D
1
Imageends_with
/auditctl
1
typeeq
daemon_abort
1
typeeq
daemon_end
1
typeeq
daemon_start
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Sigma 1 rule

Splunk 3 rules