Skip to content
Threat Feed
medium advisory

Detection of Unauthorized Linux System Log Deletion

Adversaries may attempt to evade detection and destroy forensic evidence by deleting critical Linux system logs, requiring monitoring of file deletion events for sensitive log paths.

Adversaries often target system log files on Linux systems to obfuscate their activities, destroy forensic trails, and evade detection by security operations teams. This behavior is a common component of post-exploitation activity where attackers attempt to hide indicators of compromise after gaining initial access or escalating privileges. The threat involves the removal of standard system files such as authentication records, boot logs, and kernel logs located in /var/log/ or /var/run/.

Monitoring for these deletions is essential for maintaining visibility into system integrity. However, defenders must account for legitimate system operations, such as log rotation, compression, and container management, which may legitimately interact with these files. Distinguishing malicious deletion from maintenance tasks is critical for effective alerting and preventing alert fatigue.

Impact

Successful deletion of system logs prevents incident responders from reconstructing attacker activity, identifying the scope of a breach, or determining the duration of unauthorized access. This loss of forensic evidence can significantly increase the duration and cost of an incident response engagement.

Recommendation

  • Deploy the provided Sigma rule to monitor for deletion of sensitive log files in /var/log/ and /var/run/.
  • Tune the detection logic by adding paths or process names associated with local backup tools, custom scripts, or specific log rotation utilities verified in your environment.
  • Implement file integrity monitoring (FIM) or robust centralized logging to capture deletion events before the logs themselves are purged from the local host.
  • Establish an automated response workflow to isolate systems where unauthorized log deletion is detected to prevent further data tampering.

Immediate actions

Deploy the System Log File Deletion Sigma rule to detect attempts to clear audit trails

Detection Engineering 72h

Threat Hunt

Search for instances of file deletions targeting /var/log/ directories in the last 30 days

T1070.002 medium medium confidence hunt now

Data: File deletion events

Detection coverage 1

System Log File Deletion

medium

Detects the deletion of sensitive Linux system logs which may indicate an attempt to evade detection or destroy forensic evidence.

sigma tactics: defense_evasion techniques: T1070.002 sources: file_event, linux

Detection queries are available on the platform. Get full rules →