Covering Your Tracks Flashcards
1
Q
Covering Tracks Methods
A
Disable auditing
Turn off hibernation file
Clear logs
2
Q
Disabling Auditing
A
(Ubuntu/Debian) export HISTSIZE=0
(Fedora/RHEL) systemctl auditd disable
(Windows) auditpol /set /category “System”,”Account logon” /success:disable /failure:disable
(Windows) fsutil behavior set disableastaccess 1
3
Q
Clearing Logs
A
(Windows PowerShell) clear-eventlog “WIndows PowerShell”
(Windows PowerShell) wevtutil -cl Security
cipher.exe
(Linux) echo “ “ > /var/log/auth.log
(Linux) shred file1.txt
4
Q
Defenses
A
- syslog
- SIEM
- Windows event viewer subscriptions