Prevent Command History Logging

T1690

Technique.View on attack.mitre.org

About this technique

Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they have done.

On Linux and macOS, command history is tracked in a file pointed to by the environment variable `HISTFILE`. When a user logs off a system, this information is flushed to a file in the user's home directory called `~/.bash_history`. The `HISTCONTROL` environment variable keeps track of what should be saved by the history command and eventually into the `~/.bash_history` file when a user logs out. `HISTCONTROL` does not exist by default on macOS, but can be set by the user and will be respected. The `HISTFILE` environment variable is also used in some ESXi systems.

Adversaries may clear the history environment variable (`unset HISTFILE`) or set the command history size to zero (`export HISTFILESIZE=0`) to prevent logging of commands. Additionally, `HISTCONTROL` can be configured to ignore commands that start with a space by simply setting it to "ignorespace". `HISTCONTROL` can also be set to ignore duplicate commands by setting it to "ignoredups". In some Linux systems, this is set by default to "ignoreboth" which covers both of the previous examples. This means that " ls" will not be saved, but "ls" would be saved by history. Adversaries can abuse this to operate without leaving traces by simply prepending a space to all of their terminal commands.

On Windows systems, the `PSReadLine` module tracks commands used in all PowerShell sessions and writes them to a file (`$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt` by default). Adversaries may change where these logs are saved using `Set-PSReadLineOption -HistorySavePath {File Path}`. This will cause `ConsoleHost_history.txt` to stop receiving logs. Additionally, it is possible to turn off logging to this file using the PowerShell command `Set-PSReadlineOption -HistorySaveStyle SaveNothing`.

Adversaries may also leverage a Network Device CLI on network devices to disable historical command logging (e.g. `no logging`).

Detection rules3

Rules on DetectionCode tagged with T1690.

Sigma1

RuleLevelLog source
ESXi Syslog Configuration Change Via ESXCLImediumlinux / process_creation

Splunk2

RuleTypeRiskData source
ESXi Audit TamperingTTPNULLVMWare ESXi Syslog
ESXi Syslog Config ChangeTTPNULLVMWare ESXi Syslog

Groups4

Software6

Campaigns2

Procedure examples12

Groups4

Used byProcedure example
GroupAPT38

APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment.

GroupMedusa Group

Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

GroupSea Turtle

Sea Turtle unset the Bash and MySQL history files on victim systems.

GroupUNC3886

UNC3886 has tampered with and disabled logging services on targeted systems.

Software6

Used byProcedure example
MalwareBPFDoor

BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`.

MalwareBRICKSTORM

BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input.

MalwareLine Dancer

Line Dancer can disable syslog on compromised devices.

ToolSILENTTRINITY

SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory.

MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

MalwareVIRTUALPITA

VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service.

Campaigns2

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

References3

  1. Google Cloud Threat Intelligence ESXi VIBs 2022 Open source
    Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.
  2. Microsoft about_History prevent command history Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  3. Sophos PowerShell Command History Forensics Open source
    Vikas, S. (2020, August 26). PowerShell Command History Forensics. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.