Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF034.002
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Disable Application Logging

A subject disables or materially weakens audit logging within an organizational application to prevent authentication, access, transaction, workflow, or administrative activity from being recorded.

 

The subject may disable an audit feature, change the application’s log level, exclude security-relevant event categories, suppress audit hooks, alter logging configuration files, or modify application programming interface, database, or workflow settings that control event generation. The activity may be conducted through an administrative interface, direct configuration access, a script, an application programming interface, or the underlying database.

 

Investigators should compare application configuration changes with administrative sessions, change records, database activity, identity logs, endpoint telemetry, and expected application-event volumes.