Evidence hidden by deleting system log file

이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우 언제든지 연락주시기 바랍니다.

What happened

The file {{ @file.path }} was deleted by the process {{ @process.comm }}. This may have been done to hide evidence.

Goal

Detect the removal of system log files in order to hide evidence of malicious activity.

Strategy

Monitor the file system for the deletion of specific system logs.

Triage and response

  1. Review the signal to understand how the file {{ @file.path }} was deleted.
  2. If the activity is malicious, isolate the affected host to prevent further compromise.
  3. Use related signals and other logs to find and repair the root cause.

Requires Agent version 7.27 or later.