Compliance Node Overview
MITRE ATT&CK T1070.002 (Clear Linux or Mac System Logs) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the /var/log/ directory. Subfolders in this directory categorize logs by their related functions, such as: * /var/log/messages:: General and system-related messages * /var/log/secure or /var/log/auth.log: Authentication logs * /var/log/utmp or /var/log/wtmp: Login records * /var/log/kern.log: Kernel logs *. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1029 Remote Data Storage, M1022 Restrict File and Directory Permissions, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, AC-19.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1070/002/
SHA-256 integrity: 9b2d7e8f35fc45ff1ce86de5b4e49ce712035f2dee7c197452b82c34005eb927
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1070.002: Clear Linux or Mac System Logs (https://attack.mitre.org/versions/v16/techniques/T1070/002/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access