Linux Syslog Clearing or Removal Using System Utilities

Alert on Linux commands that clear, delete, truncate, or redirect /var/log/syslog or rotate/vacuum journald logs.

FreeReviewedSigma · High · v3
Product
linux
Category
process_creation
Author
Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC (SigmaHQ), DRL 1.1
Published
2021-10-15
Updated
2026-07-31
title: Linux Syslog Clearing or Removal Using System Utilities
id: ede22a96-2bb0-4814-91cd-f3dafe290a3d
status: test
description: This rule flags Linux process executions that target /var/log/syslog for deletion, unlinking, truncation to zero length, replacement, or redirection to empty content. Attackers may use these actions to impair or erase evidence in system logging and hinder incident investigation. It relies on Linux process creation telemetry, matching command-line arguments and utility names that operate on /var/log/syslog or invoke journalctl vacuum/rotation.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.002/T1070.002.md
  - https://www.virustotal.com/gui/file/54d60fd58d7fa3475fa123985bfc1594df26da25c1f5fbc7dfdba15876dd8ac5/behavior
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_clear_syslog.yml
author: Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule Team
date: 2021-10-15
modified: 2025-10-15
tags:
  - attack.defense-impairment
  - attack.t1685.006
logsource:
  product: linux
  category: process_creation
detection:
  selection_file:
    CommandLine|contains: /var/log/syslog
  selection_command_rm:
    Image|endswith: /rm
    CommandLine|contains:
      - " -r "
      - " -f "
      - " -rf "
      - /var/log/syslog
  selection_command_unlink:
    Image|endswith: /unlink
  selection_command_mv:
    Image|endswith: /mv
  selection_command_truncate:
    Image|endswith: /truncate
    CommandLine|contains|all:
      - "0 "
      - /var/log/syslog
    CommandLine|contains:
      - "-s "
      - "-c "
      - --size
  selection_command_ln:
    Image|endswith: /ln
    CommandLine|contains|all:
      - "/dev/null "
      - /var/log/syslog
    CommandLine|contains:
      - "-sf "
      - "-sfn "
      - "-sfT "
  selection_command_cp:
    Image|endswith: /cp
    CommandLine|contains: /dev/null
  selection_command_shred:
    Image|endswith: /shred
    CommandLine|contains: "-u "
  selection_unique_other:
    CommandLine|contains:
      - " > /var/log/syslog"
      - " >/var/log/syslog"
      - " >| /var/log/syslog"
      - ": > /var/log/syslog"
      - :> /var/log/syslog
      - :>/var/log/syslog
      - ">|/var/log/syslog"
  selection_unique_journalctl:
    CommandLine|contains:
      - journalctl --vacuum
      - journalctl --rotate
  condition: (selection_file and 1 of selection_command_*) or 1 of selection_unique_*
falsepositives:
  - Log rotation.
  - Maintenance.
level: high
license: DRL-1.1
related:
  - id: 3fcc9b35-39e4-44c0-a2ad-9e82b6902b31
    type: derived