{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/logs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HTTP Server","IIS"],"_cs_severities":["medium"],"_cs_tags":["defense-evasion","file-integrity","logs","cross-platform"],"_cs_type":"advisory","_cs_vendors":["Apache","Microsoft"],"content_html":"\u003cp\u003eAdversaries frequently target web server access logs during the post-exploitation phase to cover their tracks and impede incident response. By deleting these files, attackers aim to destroy records of their initial access, C2 communication, or internal reconnaissance activities. This behavior is cross-platform, affecting common web server architectures including Microsoft IIS, Apache, and HTTPd. Detection engineering teams should monitor for file deletion events occurring within standard directory paths dedicated to log storage. While this activity is often malicious, defenders must differentiate between attacker-led indicator removal and routine administrative tasks such as log rotation, automated backups, or environment resets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized access to a web server via exploit or credential misuse.\u003c/li\u003e\n\u003cli\u003eAttacker executes commands to explore the file system and locate web server log directories.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the specific log files that record their malicious activities.\u003c/li\u003e\n\u003cli\u003eAttacker issues delete commands (e.g., 'del' on Windows or 'rm' on Linux/macOS) to target the log files.\u003c/li\u003e\n\u003cli\u003eThe OS records a 'file deletion' event within the EDR or system logging subsystem.\u003c/li\u003e\n\u003cli\u003eSecurity tools trigger an alert based on the file path matching web server log conventions.\u003c/li\u003e\n\u003cli\u003eAttacker continues unauthorized activity with reduced visibility for responders.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deletion of web server access logs results in the permanent loss of critical forensic data required for determining the scope of a breach, identifying the attacker's IP address, and mapping the timeline of an incident. Without these logs, defenders may be unable to confirm if sensitive data was exfiltrated or which specific web application vulnerabilities were exploited, forcing a reliance on secondary, potentially less reliable telemetry.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the detection rule below to identify unauthorized file deletion events targeting web server logs.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of authorized log rotation processes, backup scripts, and maintenance tasks; use these as filters to reduce noise.\u003c/li\u003e\n\u003cli\u003eAudit access controls on web server log directories to restrict write and delete permissions to service accounts and authorized administrative roles only.\u003c/li\u003e\n\u003cli\u003eCorrelate log deletion alerts with preceding web server requests or unauthorized process executions to confirm malicious intent.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T13:11:06Z","date_published":"2026-09-18T19:09:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-websvr-log-deletion/","summary":"Adversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.","title":"Detection of Web Server Access Log Deletion","url":"https://feed.craftedsignal.io/briefs/2026-09-websvr-log-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Logs","version":"https://jsonfeed.org/version/1.1"}