Detection rules › Sigma

Linux Logs Clearing Attempts

Status
stable
Severity
medium
Log source
category process_creation, product linux
Author
Ömer Günal, oscd.community
Source
github.com/SigmaHQ/sigma

Detects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories. Adversaries often try to clear logs to cover their tracks after performing malicious activities.

Known false positives

  • Legitimate administration activities

MITRE ATT&CK coverage

Telemetry coverage

PlatformRecord / event type
LinuxEvent ID 1: Process Create

Rule body

title: Linux Logs Clearing Attempts
id: 80915f59-9b56-4616-9de0-fd0dea6c12fe
status: stable
description: |
    Detects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories.
    Adversaries often try to clear logs to cover their tracks after performing malicious activities.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.002/T1070.002.md
author: Ömer Günal, oscd.community
date: 2020-10-07
modified: 2026-03-18
tags:
    - attack.defense-impairment
    - attack.t1685.006
logsource:
    product: linux
    category: process_creation
detection:
    selection:
        Image|endswith:
            - '/rm'    # covers /rmdir as well
            - '/rmdir'
            - '/shred'
            - '/unlink'
        CommandLine|contains:
            - '/var/log'
            - '/var/spool/mail'
    filter_main_legit_systat:
        Image|endswith: '/rm'
        CommandLine|startswith: 'rm -f /var/log/sysstat/'
    filter_main_dmseg:
        Image|endswith: '/rm'
        CommandLine|startswith: 'rm -f -- /var/log//dmesg' # // before dmesg is not typo
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Legitimate administration activities
level: medium

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_*

Stage 1: selection

selection:
    Image|endswith:
        - '/rm'
        - '/rmdir'
        - '/shred'
        - '/unlink'
    CommandLine|contains:
        - '/var/log'
        - '/var/spool/mail'

Stage 2: not filter_main_*

filter_main_legit_systat:
    Image|endswith: '/rm'
    CommandLine|startswith: 'rm -f /var/log/sysstat/'
filter_main_dmseg:
    Image|endswith: '/rm'
    CommandLine|startswith: 'rm -f -- /var/log//dmesg'

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
CommandLinestarts_withrm -f -- /var/log//dmesgexcludes:CommandLine field:"CommandLine" value:"rm -f -- /var/log//dmesg"
Imageends_with/rmexcludes:Image field:"Image" value:"/rm"
CommandLinestarts_withrm -f /var/log/sysstat/excludes:CommandLine field:"CommandLine" value:"rm -f /var/log/sysstat/"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • /var/log
  • /var/spool/mail
field:"CommandLine" kind:match
Imageends_with
  • /rm
  • /rmdir
  • /shred
  • /unlink
field:"Image" kind:ends_with