Syslog Clearing or Removal Via System Utilities

 Original Source: [Sigma source]
Title: Syslog Clearing or Removal Via System Utilities
Status: test
Description:Detects specific commands commonly used to remove or empty the syslog. Which is a technique often used by attacker as a method to hide their tracks
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.002/T1070.002.md
  -https://www.virustotal.com/gui/file/54d60fd58d7fa3475fa123985bfc1594df26da25c1f5fbc7dfdba15876dd8ac5/behavior
Author: Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date: 2021-10-15
modified:2025-10-15
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.006'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection_file:
    CommandLine|contains: '/var/log/syslog'
  selection_command_rm:
    Image|endswith: '/rm'
    CommandLine|contains:
      -' -r '
      -' -f '
      -' -rf '
      -'/var/log/syslog'

  selection_command_unlink:
    Image|endswith: '/unlink'
  selection_command_mv:
    Image|endswith: '/mv'
  selection_command_truncate:
    Image|endswith: '/truncate'
    CommandLine|contains|all:
      -'0 '
      -'/var/log/syslog'

    CommandLine|contains:
      -'-s '
      -'-c '
      -'--size'

  selection_command_ln:
    Image|endswith: '/ln'
    CommandLine|contains|all:
      -'/dev/null '
      -'/var/log/syslog'

    CommandLine|contains:
      -'-sf '
      -'-sfn '
      -'-sfT '

  selection_command_cp:
    Image|endswith: '/cp'
    CommandLine|contains: '/dev/null'
  selection_command_shred:
    Image|endswith: '/shred'
    CommandLine|contains: '-u '
  selection_unique_other:
    CommandLine|contains:
      -' > /var/log/syslog'
      -' >/var/log/syslog'
      -' >| /var/log/syslog'
      -': > /var/log/syslog'
      -':> /var/log/syslog'
      -':>/var/log/syslog'
      -'>|/var/log/syslog'

  selection_unique_journalctl:
    CommandLine|contains:
      -'journalctl --vacuum'
      -'journalctl --rotate'

  condition:(selection_file and 1 of selection_command_*) or 1 of selection_unique_*
Falsepositives:
  -Log rotation.
  -Maintenance.
Level: high