Detections
- Home
- - Detections
- -DT053
- ID: DT053
- Created: 09th June 2024
- Updated: 09th June 2024
- Platforms: Linux, MacOS
- Contributor: The ITM Team
Missing .bash_history File
The .bash_history file, located within a user's directory on MacOS and Linux, is written with command history from shell sessions.
If the file is missing, this could indicate that it has been deleted, if a user account has used a shell utility previously.
Sections
ID | Name | Description |
---|---|---|
AF001 | Clear Command History | A subject clears command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. |
AF001.002 | Clear Bash History | A subject clears bash terminal command history to prevent executed commands from being reviewed, disclosing information about the subject’s activities. The Command Prompt on Windows only stores command history within the current session, once Command Prompt is closed, the history is lost. On Linux-based operating systems different terminal software may store command history in various locations, with the most common being On MacOS the Terminal utility will write command history to |