// MITRE ATT&CK

T1685.004 · Disable or Modify Linux Audit System Log

🎯 Defense Impairment Linux Sub-technique

Sub-technique of T1685 · Disable or Modify Tools.

Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system ...

How to detect & mitigate it

Detecting Disable or Modify Linux Audit System Log starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.