Detections
- Home
- - Detections
- -DT002
- ID: DT002
- Created: 25th May 2024
- Updated: 14th June 2024
- Platform: Windows
- Contributor: The ITM Team
ConsoleHost_history.txt File Missing
If the ConsoleHost_history.txt
file located in C:\Users\%username%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine
, is missing, this indicates that the file has been deleted. This may represent an anti-forensics technique if the subject in question is known to have used PowerShell any time.
Sections
ID | Name | Description |
---|---|---|
AF001 | Clear Command History | A subject clears command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. |
AF001.001 | Clear PowerShell History | A subject clears PowerShell command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. PowerShell stores command history in the context of a user account. This file is located at A subject can delete their own A subject may attempt to use the |