T1685.004 · Disable or Modify Linux Audit System Log
Sub-técnica de T1685 · Disable or Modify Tools.
Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system ...
¿Cómo detectarlo y mitigarlo?
Técnicas relacionadas
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.