Suspicious History File Operations - Linux

 Original Source: [Sigma source]
Title: Suspicious History File Operations - Linux
Status: test
Description:Detects commandline operations on shell history files
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.003/T1552.003.md
Author: Mikhail Larin, oscd.community
Date: 2020-10-17
modified:2022-11-28
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.003'
Logsource:
  • product: linux
  • service: auditd
Detection:
  execve:
    type: 'EXECVE'
  history:
    - '.bash_history'
    - '.zsh_history'
    - '.zhistory'
    - '.history'
    - '.sh_history'
    - 'fish_history'
  condition:execve and history
Falsepositives:
  -Legitimate administrative activity
  -Legitimate software, cleaning hist file
Level: medium