detections
- ID: DT014
- Created: 30th May 2024
- Updated: 14th June 2024
- Platforms: WindowsLinuxMacOS
- Contributor: The ITM Team
Utilize Cold Storage for Logs
By autonomously collecting log files from a system and transporting them to another system, such as a SIEM collector, they are typically no longer accessible by the subject, preventing them from being able to delete them. These can aid in investigations where a subject has deleted local logs.
Sections
| ID | Name | Description |
|---|---|---|
| AF002 | Log Deletion | The subject deliberately deletes logs to eliminate records of their activity and hinder subsequent investigation. This may include host-based logs (e.g., Windows Event Logs, Linux audit logs), application logs (e.g., authentication or access records), or network-level logs (e.g., firewall or proxy logs).
Deletion may be selective by targeting specific time ranges, event types, or identifiers, or more broad by wiping entire log files or directories to prevent attribution or timeline reconstruction. |
| AF026 | Log Modification | The subject intentionally alters or removes log entries, either at the host, application, or network level, in a deliberate attempt to conceal or misrepresent their actions. This behavior is typically executed to frustrate forensic reconstruction during an investigation and may include deletion of individual log lines, rewriting timestamps, or manipulating source IPs or usernames.
Subjects engaging in this technique may use native administrative tools (e.g., PowerShell, auditpol, journalctl), third-party log scrubbers, or direct file system access to tamper with |
| AF002.001 | Clear Windows Event Logs | A subject clears Windows Event logs to conceal evidence of their activities. Windows Event Logs store various types of information, such as system errors, application events, security auditing messages, and other operational events. The logs are stored in Windows Event Logs can be cleared using the Event Viewer utility, provided the user account has administrative privileges. |
| AF002.002 | Clear Linux System Logs | A subject deletes Linux system logs to obscure or eliminate evidence of an infringement. Linux log files, such as authentication attempts, sudo usage, system errors, and audit trails, serve as critical forensic artifacts during post-incident analysis. These logs are commonly stored in
Deletion may occur manually via the |
| AF002.003 | Clear macOS System Logs | A subject deletes macOS system logs to obscure or eliminate evidence of an infringement. macOS stores a range of log data, including authentication attempts, application launches, process crashes, system events, and security audits, within
Deletion may occur manually via the |
| AF026.001 | Host Log Modification | A subject intentionally alters host-based log records to conceal, misattribute, or misrepresent activity conducted on an endpoint, server, or other operating system.
The subject may change timestamps, account names, event identifiers, source addresses, command details, or action outcomes within Windows Event Logs, Linux system or audit logs, macOS logs, security-agent logs, or other locally stored records. Modification may be performed using administrative tools, scripts, third-party log scrubbers, or direct access to
Investigators should compare local records with centrally forwarded logs, Endpoint Detection and Response (EDR) telemetry, process execution records, file metadata, and File Integrity Monitoring (FIM) events. This Sub-section applies where log content is altered but the record or log remains present. |
| AF026.002 | Application Log Modification | A subject intentionally alters audit, authentication, access, transaction, or administrative records generated by an organizational application to conceal or misrepresent activity conducted through that application.
The subject may change the recorded actor, timestamp, source address, action, affected object, approval state, or result. Modification may be performed through application administration functionality, an Application Programming Interface (API), direct database access, scripts, or access to the underlying log repository.
Investigators should compare application records with identity logs, database activity, endpoint telemetry, web proxy records, workflow history, and relevant business records. |
| AF026.003 | Network and Security Device Log Modification | A subject intentionally alters records generated by network or security infrastructure to conceal, misattribute, or misrepresent network activity.
Affected records may include firewall, proxy, Virtual Private Network (VPN), Domain Name System (DNS), Network Access Control (NAC), intrusion detection, router, switch, or secure web gateway logs. The subject may change source or destination addresses, ports, protocols, requested domains, authenticated identities, timestamps, security decisions, or action outcomes.
Modification may occur on the originating device, its management controller, a centralized collector, or another downstream repository. Investigators should compare device logs with NetFlow, packet inspection, endpoint telemetry, DNS records, identity events, and independently collected network records. |
| AF026.004 | Cloud Audit Log Modification | A subject intentionally alters cloud audit records or exported cloud log data to conceal, misattribute, or misrepresent activity conducted within a cloud environment.
The subject may replace or modify log objects held in cloud storage, alter records within a log analytics workspace or data lake, manipulate a custom logging pipeline, or insert fabricated events into a downstream repository. Changes may affect the recorded identity, source address, operation, resource, timestamp, request parameters, or outcome.
Provider-maintained audit histories may prevent direct modification by tenant administrators. Investigators should therefore compare native provider records with exported copies, storage-object versions, logging-pipeline configurations, access records, and Security Information and Event Management (SIEM) data. |
| AF034.001 | Disable Host Logging | A subject disables or materially weakens logging on an endpoint, server, appliance, or other host to prevent operating-system and local security activity from being recorded.
The subject may stop an audit or logging service, disable event channels, change audit policy, remove monitored event categories, suppress command or process logging, or modify host configuration so that security-relevant events are no longer generated.
Investigators should examine service-state changes, audit-policy modifications, logging configuration files, privileged commands, process execution, and unexpected gaps in host telemetry. |
| AF034.002 | Disable Application Logging | A subject disables or materially weakens audit logging within an organizational application to prevent authentication, access, transaction, workflow, or administrative activity from being recorded.
The subject may disable an audit feature, change the application’s log level, exclude security-relevant event categories, suppress audit hooks, alter logging configuration files, or modify application programming interface, database, or workflow settings that control event generation. The activity may be conducted through an administrative interface, direct configuration access, a script, an application programming interface, or the underlying database.
Investigators should compare application configuration changes with administrative sessions, change records, database activity, identity logs, endpoint telemetry, and expected application-event volumes. |
| AF034.003 | Disable Network and Security Device Logging | A subject disables or materially weakens logging on network or security infrastructure to prevent network activity, access decisions, configuration changes, or security events from being recorded.
Affected infrastructure may include firewalls, proxies, routers, switches, Virtual Private Network services, Domain Name System services, Network Access Control systems, intrusion detection systems, secure web gateways, or other security appliances. The subject may disable local logging, remove event categories, reduce log severity, stop flow generation, disable security alerts, or alter the device’s logging destination.
Investigators should review device configuration history, management-plane access, privileged sessions, change records, collector status, NetFlow, packet inspection, endpoint telemetry, and parallel network sensors. |
| AF034.004 | Disable Cloud and Identity Audit Logging | A subject disables or materially weakens native audit logging within a cloud platform, identity provider, cloud account, subscription, project, tenant, or Software as a Service environment.
The subject may disable audit services, remove data-event categories, alter diagnostic settings, disable identity or administrative audit events, exclude resources from monitoring, or change the destination to which native audit records are sent. The activity may affect cloud control-plane actions, resource access, authentication, role assignments, application administration, or other security-relevant events.
Investigators should review provider-maintained administrative records, privileged-role activation, configuration changes, logging-resource changes, policy modifications, and discrepancies between native audit sources and exported records. |
| AF034.005 | Disable Log Forwarding and Collection | A subject disables or interferes with the mechanisms used to transmit, collect, process, or ingest logs into a centralized repository, archive, data lake, or Security Information and Event Management platform.
The subject may stop or reconfigure a forwarding agent, disable syslog transmission, remove a collector subscription, change a destination address, revoke a pipeline identity, block required network traffic, alter routing or filtering rules, or suppress specific event sources before ingestion. Local records may continue to exist even though investigators lose centralized visibility.
Investigators should identify missing source heartbeats, ingestion gaps, forwarding-agent health changes, configuration modifications, authentication failures, queue backlogs, rejected events, and discrepancies between local records and centrally retained data. |
| AF034.006 | Disable Log Retention Controls | A subject disables or materially weakens controls intended to preserve logs for a defined period, causing records to expire, become unavailable, or lose protected status before they are likely to be reviewed.
The subject may shorten a retention period, remove an event source from archival storage, disable object lock or immutability, alter storage lifecycle rules, reduce repository capacity, change index-retention settings, or remove a protected logging tier. The configuration change may affect future records or accelerate the removal of records already held within a managed platform.
Investigators should review retention-policy history, lifecycle-rule changes, storage configuration, object-lock status, privileged access, change approvals, archive coverage, and the oldest available record for each expected source. |