Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF034.001
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Platforms: WindowsLinuxMacOS
  • Contributor: The ITM Team

Disable Host Logging

A subject disables or materially weakens logging on an endpoint, server, appliance, or other host to prevent operating-system and local security activity from being recorded.

 

The subject may stop an audit or logging service, disable event channels, change audit policy, remove monitored event categories, suppress command or process logging, or modify host configuration so that security-relevant events are no longer generated.

 

Investigators should examine service-state changes, audit-policy modifications, logging configuration files, privileged commands, process execution, and unexpected gaps in host telemetry.