BIOC Informational

Log deletion via command-line tool

An attacker may use the rm command to remove traces of their activities.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal (T1070)
Indicator:

Process action type = execution AND target process cmd = */var/log/* , */var/audit* , */var/spool/mail* AND target process name = rm

Preventable: yes