Tag
medium
advisory
Tampering of Shell Command-Line History
1 rule 1 TTPAdversaries manipulate shell command-line history files and environment variables on Unix-like systems to evade detection and hinder post-compromise forensic analysis.
defense-evasion
linux
macos
shell-history
persistence
1r
1t
high
advisory
Linux Shell History Clearing via Environment Variables
2 rules 1 TTPAttackers may clear shell history on Linux systems to evade detection by manipulating environment variables related to shell history, such as HISTSIZE and HISTFILE, to prevent command logging.
Linux
defense-evasion
shell-history
2r
1t