Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF034
- Created: 07th July 2026
- Updated: 07th July 2026
- MITRE ATT&CK®: T1685T1685.001T1685.002T1685.004
- Contributor: The ITM Team
Disable Logging
A subject disables, suppresses, or materially weakens logging to prevent activity from being recorded. This behavior targets the systems, services, configurations, agents, or pipelines responsible for generating, collecting, forwarding, or retaining event data. By preventing telemetry from being created or preserved, the subject reduces the evidentiary record available to investigators and may create a deliberate visibility gap around unauthorized activity.
Disable Logging may involve stopping audit services, changing audit policy, disabling log forwarding, modifying retention settings, suppressing application logs, impairing endpoint telemetry, or preventing specific categories of events from being written. It may occur on endpoints, servers, cloud workloads, identity platforms, administrative systems, or security tooling where the subject has sufficient access to influence logging behavior.
Subsections (6)
| ID | Name | Description |
|---|---|---|
| AF034.002 | Disable Application Logging | A subject disables or materially weakens audit logging within an organizational application to prevent authentication, access, transaction, workflow, or administrative activity from being recorded.
The subject may disable an audit feature, change the application’s log level, exclude security-relevant event categories, suppress audit hooks, alter logging configuration files, or modify application programming interface, database, or workflow settings that control event generation. The activity may be conducted through an administrative interface, direct configuration access, a script, an application programming interface, or the underlying database.
Investigators should compare application configuration changes with administrative sessions, change records, database activity, identity logs, endpoint telemetry, and expected application-event volumes. |
| AF034.004 | Disable Cloud and Identity Audit Logging | A subject disables or materially weakens native audit logging within a cloud platform, identity provider, cloud account, subscription, project, tenant, or Software as a Service environment.
The subject may disable audit services, remove data-event categories, alter diagnostic settings, disable identity or administrative audit events, exclude resources from monitoring, or change the destination to which native audit records are sent. The activity may affect cloud control-plane actions, resource access, authentication, role assignments, application administration, or other security-relevant events.
Investigators should review provider-maintained administrative records, privileged-role activation, configuration changes, logging-resource changes, policy modifications, and discrepancies between native audit sources and exported records. |
| AF034.001 | Disable Host Logging | A subject disables or materially weakens logging on an endpoint, server, appliance, or other host to prevent operating-system and local security activity from being recorded.
The subject may stop an audit or logging service, disable event channels, change audit policy, remove monitored event categories, suppress command or process logging, or modify host configuration so that security-relevant events are no longer generated.
Investigators should examine service-state changes, audit-policy modifications, logging configuration files, privileged commands, process execution, and unexpected gaps in host telemetry. |
| AF034.005 | Disable Log Forwarding and Collection | A subject disables or interferes with the mechanisms used to transmit, collect, process, or ingest logs into a centralized repository, archive, data lake, or Security Information and Event Management platform.
The subject may stop or reconfigure a forwarding agent, disable syslog transmission, remove a collector subscription, change a destination address, revoke a pipeline identity, block required network traffic, alter routing or filtering rules, or suppress specific event sources before ingestion. Local records may continue to exist even though investigators lose centralized visibility.
Investigators should identify missing source heartbeats, ingestion gaps, forwarding-agent health changes, configuration modifications, authentication failures, queue backlogs, rejected events, and discrepancies between local records and centrally retained data. |
| AF034.006 | Disable Log Retention Controls | A subject disables or materially weakens controls intended to preserve logs for a defined period, causing records to expire, become unavailable, or lose protected status before they are likely to be reviewed.
The subject may shorten a retention period, remove an event source from archival storage, disable object lock or immutability, alter storage lifecycle rules, reduce repository capacity, change index-retention settings, or remove a protected logging tier. The configuration change may affect future records or accelerate the removal of records already held within a managed platform.
Investigators should review retention-policy history, lifecycle-rule changes, storage configuration, object-lock status, privileged access, change approvals, archive coverage, and the oldest available record for each expected source. |
| AF034.003 | Disable Network and Security Device Logging | A subject disables or materially weakens logging on network or security infrastructure to prevent network activity, access decisions, configuration changes, or security events from being recorded.
Affected infrastructure may include firewalls, proxies, routers, switches, Virtual Private Network services, Domain Name System services, Network Access Control systems, intrusion detection systems, secure web gateways, or other security appliances. The subject may disable local logging, remove event categories, reduce log severity, stop flow generation, disable security alerts, or alter the device’s logging destination.
Investigators should review device configuration history, management-plane access, privileged sessions, change records, collector status, NetFlow, packet inspection, endpoint telemetry, and parallel network sensors. |
Preventions (3)
Detections (5)
MITRE ATT&CK® Mapping (4)
ATT&CK Enterprise Matrix Version 19.2