// MITRE ATT&CK

T1685.006 · Clear Linux or Mac System Logs

🎯 Defense Impairment LinuxmacOS Sub-technique

Sub-technique of T1685 · Disable or Modify Tools.

Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the `/var/log/` directory. Subfolders in this directory categorize logs by their related func...

How to detect & mitigate it

Detecting Clear Linux or Mac System Logs starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.