Detections
- Home
- - Detections
- -DT001
- ID: DT001
- Created: 25th May 2024
- Updated: 14th June 2024
- Platform: Windows
- Contributor: The ITM Team
ConsoleHost_history.txt Created Timestamp Discrepancy
Recent modifications to the ConsoleHost_history.txt
file located in C:\Users\%username%\AppData\Roa
ming\Microsoft\Windows\PowerShell\PSReadLine may indicate the file has been deleted and subsequently automatically recreated by the Operating System. This may represent an anti-forensics technique if the subject in question is known to have used PowerShell any time prior to the “Created” timestamp of the ConsoleHost_history.txt file.
Sections
ID | Name | Description |
---|---|---|
AF001 | Clear Command History | A subject clears command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. |
AF001.001 | Clear PowerShell History | A subject clears PowerShell command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. PowerShell stores command history in the context of a user account. This file is located at A subject can delete their own A subject may attempt to use the |