Esc
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.
Disable or Modify Linux Audit System Log - T1685.004
(Enterprise Technique)
Definition
Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system activity such as process, network, file, and login events based on pre-configured rules.
D3FEND Inferred Relationships
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.