Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF034.003
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Disable Network and Security Device Logging

A subject disables or materially weakens logging on network or security infrastructure to prevent network activity, access decisions, configuration changes, or security events from being recorded.

 

Affected infrastructure may include firewalls, proxies, routers, switches, Virtual Private Network services, Domain Name System services, Network Access Control systems, intrusion detection systems, secure web gateways, or other security appliances. The subject may disable local logging, remove event categories, reduce log severity, stop flow generation, disable security alerts, or alter the device’s logging destination.

 

Investigators should review device configuration history, management-plane access, privileged sessions, change records, collector status, NetFlow, packet inspection, endpoint telemetry, and parallel network sensors.