Skip to content

Hide Navigation Hide TOC

Commands to Clear or Remove the Syslog (3fcc9b35-39e4-44c0-a2ad-9e82b6902b31)

Detects specific commands commonly used to remove or empty the syslog. Which is often used by attacker as a method to hide their tracks

Cluster A Galaxy A Cluster B Galaxy B Level
Clear Linux or Mac System Logs - T1070.002 (2bce5b30-7014-4a5d-ade7-12913fe6ac36) Attack Pattern Commands to Clear or Remove the Syslog (3fcc9b35-39e4-44c0-a2ad-9e82b6902b31) Sigma-Rules 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Clear Linux or Mac System Logs - T1070.002 (2bce5b30-7014-4a5d-ade7-12913fe6ac36) Attack Pattern 2