Linux Commands Clearing or Removing /var/log/syslog

Flags Linux activity that clears, deletes, or redirects /var/log/syslog, a likely attempt to impair logging.

FreeReviewedSigma · High · v3
Product
linux
Author
Max Altgelt (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-09-10
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags Linux shell activity that removes or empties the system syslog file by matching common destructive commands targeting /var/log/syslog. Attackers may use this to hinder forensics by deleting or overwriting logging traces. The detection relies on process or command-line telemetry that captures the executed command strings.

Related detections5 linkedT1565.001 — drag to rearrange
Linux process-created writes to sensitive or critical files via shell redirection or editors
Linux Shell History File Deletion via rm/unlink/shred
Azure Activity Logs: Device or Device Configuration Modified or Deleted
Azure Activity Logs: DNS Zone Write or Delete Operations
Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
Linux Commands Clearing or Removing /var/log/syslog
Pivot detection · T1565.001 · 5 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.