Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF034.003
- Created: 05th August 2026
- Updated: 05th August 2026
- Contributor: The ITM Team
Disable Network and Security Device Logging
A subject disables or materially weakens logging on network or security infrastructure to prevent network activity, access decisions, configuration changes, or security events from being recorded.
Affected infrastructure may include firewalls, proxies, routers, switches, Virtual Private Network services, Domain Name System services, Network Access Control systems, intrusion detection systems, secure web gateways, or other security appliances. The subject may disable local logging, remove event categories, reduce log severity, stop flow generation, disable security alerts, or alter the device’s logging destination.
Investigators should review device configuration history, management-plane access, privileged sessions, change records, collector status, NetFlow, packet inspection, endpoint telemetry, and parallel network sensors.