Prevent Command History Logging T1690

Tactic: Defense Impairment

Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they have done.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (6 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Message2contains 2, in 1*local*, *remote*, esxcli, esxcli system auditrecords, syslog config set
sourcetype2in 2vmw-syslog, vmware:esxlog*
CommandLine1contains 1 set, config, syslog
Image1ends_with 1/esxcli
aws::eventName1eq 1DeleteModelInvocationLoggingConfiguration
aws::eventSource1eq 1bedrock.amazonaws.com

Top indicator values (14 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypein
vmw-syslog
223
sourcetypein
vmware:esxlog*
223
CommandLinecontains
set
12
CommandLinecontains
config
116
CommandLinecontains
syslog
1
CommandLinecontains
system
19
Imageends_with
/esxcli
19
Messagecontains
esxcli
12
Messagecontains
esxcli system auditrecords
1
Messagecontains
syslog config set
1
Messagein
*local*
1
Messagein
*remote*
1
aws::eventNameeq
DeleteModelInvocationLoggingConfiguration
1
aws::eventSourceeq
bedrock.amazonaws.com
19

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Messagecontains
[shell
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 1 rule

Splunk 2 rules

Panther 1 rule