This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Syslog Clearing or Removal Via System Utilities
Original Source:
[Sigma source]
Title:
Syslog Clearing or Removal Via System Utilities
Status:
test
Description:
Detects specific commands commonly used to remove or empty the syslog. Which is a technique often used by attacker as a method to hide their tracks
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.002/T1070.002.md
-https://www.virustotal.com/gui/file/54d60fd58d7fa3475fa123985bfc1594df26da25c1f5fbc7dfdba15876dd8ac5/behavior
Author:
Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date:
2021-10-15
modified:
2025-10-15
Tags:
-'attack.defense-impairment'
-'attack.t1685.006'
Logsource:
product: linux
category: process_creation
Detection:
selection_file:
CommandLine|contains
:
'/var/log/syslog'
selection_command_rm:
Image|endswith
:
'/rm'
CommandLine|contains
:
-' -r '
-' -f '
-' -rf '
-'/var/log/syslog'
selection_command_unlink:
Image|endswith
:
'/unlink'
selection_command_mv:
Image|endswith
:
'/mv'
selection_command_truncate:
Image|endswith
:
'/truncate'
CommandLine|contains|all
:
-'0 '
-'/var/log/syslog'
CommandLine|contains
:
-'-s '
-'-c '
-'--size'
selection_command_ln:
Image|endswith
:
'/ln'
CommandLine|contains|all
:
-'/dev/null '
-'/var/log/syslog'
CommandLine|contains
:
-'-sf '
-'-sfn '
-'-sfT '
selection_command_cp:
Image|endswith
:
'/cp'
CommandLine|contains
:
'/dev/null'
selection_command_shred:
Image|endswith
:
'/shred'
CommandLine|contains
:
'-u '
selection_unique_other:
CommandLine|contains
:
-' > /var/log/syslog'
-' >/var/log/syslog'
-' >| /var/log/syslog'
-': > /var/log/syslog'
-':> /var/log/syslog'
-':>/var/log/syslog'
-'>|/var/log/syslog'
selection_unique_journalctl:
CommandLine|contains
:
-'journalctl --vacuum'
-'journalctl --rotate'
condition
:
(selection_file and 1 of selection_command_*) or 1 of selection_unique_*
Falsepositives:
-Log rotation.
-Maintenance.
Level:
high