Rule Info
Name
Critical Log File Deletion on Linux System
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects deletion of critical log files on Linux systems that may indicate log tampering or evidence destruction.
This technique can be used by attackers to cover their tracks after gaining unauthorized access to a system.
Reference
Internal Research
Date
2026-03-26 00:00:00
Modified
None
Id
e96d02e6-5dec-4318-a576-d3b146d9d8c0
Tags
attack.defense-evasion attack.t1070.002
Type
Nextron Sigma feed only (private)
