Disable or Modify Tools: Clear Linux or Mac System Logs T1685.006
Tactic: Defense Impairment
Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the `/var/log/` directory. Subfolders in this directory categorize logs by their related functions, such as:
Events covered
5 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| Linux-Auditd | Event ID 1300 | SYSCALL |
| Linux-Auditd | Event ID 1309 | EXECVE |
| Linux-Auditd | Event ID 1327 | PROCTITLE |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 13 rules share fields, values, and exclusions.
Fields filtered most (15 distinct)
These fields appear most often in rule filters.
Top indicator values (95 distinct)
These values appear most often in rule predicates.
Exclusions (23 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint
Sigma 4 rules
- Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
- Indicator Removal on Host - Clear Mac System Logs
- Linux Logs Clearing Attempts
- Syslog Clearing or Removal Via System Utilities
Elastic 8 rules
- Attempt to Clear Kernel Ring Buffer
- Attempt to Clear Kernel Ring Buffer via Dmesg
- Attempt to Clear Logs via Journalctl
- Attempt to Clear Logs via Journalctl
- File Creation in /var/log via Suspicious Process
- Loadable Kernel Module Load Followed by Log Clearing
- Multiple System Log Files Deletion
- System Log File Deletion