Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.1 KB

MATCH-S00688.md

File metadata and controls

33 lines (26 loc) · 1.1 KB

Rules: Bash History Tampering

Description

This rule monitors for various methods of deleting or otherwise tampering with .bash_history files which store command history on Linux machines.

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Bash History Tampering
Summary Expression The command history on host {{device_hostname}} was manipulated by user {{user_username}}
Score/Severity Static: 7
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1070, _mitreAttackTechnique:T1070.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username