MITRE ATT&CK Technique
T1070.002Clear Linux or Mac System Logs
- First Reported
- Jul 17, 2026
- Latest Reported
- Sep 29, 2026
Official Description
Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the <code>/var/log/</code> directory. Subfolders in this directory categorize logs by their related functions, such as:(Citation: Linux Logs)
* <code>/var/log/messages:</code>: General and system-related messages
* <code>/var/log/secure</code> or <code>/var/log/auth.log</code>: Authentication logs
* <code>/var/log/utmp</code> or <code>/var/log/wtmp</code>: Login records
* <code>/var/log/kern.log</code>: Kernel logs
* <code>/var/log/cron.log</code>: Crond logs
* <code>/var/log/maillog</code>: Mail server logs
* <code>/var/log/httpd/</code>: Web server access and error logs
* <code>/var/log/messages:</code>: General and system-related messages
* <code>/var/log/secure</code> or <code>/var/log/auth.log</code>: Authentication logs
* <code>/var/log/utmp</code> or <code>/var/log/wtmp</code>: Login records
* <code>/var/log/kern.log</code>: Kernel logs
* <code>/var/log/cron.log</code>: Crond logs
* <code>/var/log/maillog</code>: Mail server logs
* <code>/var/log/httpd/</code>: Web server access and error logs
- Tactics
- Stealth
- Platforms
- Linux, macOS
- MITRE Version
- 1.0
- Last Modified
- Apr 14, 2026
Reported Context (3)
- The article describes an actor regex-based log wiper targeting appliance web-access log entries around web-shell paths. Mandiant Details Active Exploitation of Citrix NetScaler Zero-Days and Defense Measures
- cleanup_target.sh was designed to delete Linux system and service logs while preserving the installed MeshCentral agent. Exposed Directory Reveals FortiGate and MeshCentral Intrusion Targeting Thai Broadband Provider
- KNUCKLEBALL cleared the Java agents' log files before injection and linked their paths to /dev/null to prevent retained logs. Volexity Details Zero-Day Exploitation of SonicWall SMA VPN Appliances
CVE (15)
Malware (5)
People (16)
Threat Actors (2)
MITRE ATT&CK (28)
Vendors (8)
Products (13)
Tools (9)
Industries (6)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.