Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004
Tactic: Defense Impairment
Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system activity such as process, network, file, and login events based on pre-configured rules.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Linux-Auditd | Event ID 1200 | DAEMON_START |
| Linux-Auditd | Event ID 1201 | DAEMON_END |
| Linux-Auditd | Event ID 1202 | DAEMON_ABORT |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (4 distinct)
These fields appear most often in rule filters.
Top indicator values (6 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint