1200KM / simulation
T1070.003 Clear Command History — Attack Simulation
In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done. On Linux and macOS, these command histories can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by…
Technique description
In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done. On Linux and macOS, these command histories can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Set Custom AddToHistoryHandler to Avoid History File Logging
Procedure 1d0d9aa6-6111-4f89-927b-53e8afae7f94; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Clear PowerShell Session History
Procedure 22c779cd-9445-4d3e-a136-f75adbf0315f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Bash history (ln dev/null)
Procedure 23d348f3-cc5c-4ba9-bd0a-ae09069f0914; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Prevent Powershell History Logging
Procedure 2f898b81-3e97-4abb-bc3f-a95138988370; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Clear Bash history (truncate)
Procedure 47966a1d-df4f-4078-af65-db6d9aa20739; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Use Space Before Command to Avoid Logging to History
Procedure 53b03a54-4529-4992-852d-a00b4b7215a6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Docker Container Logs
Procedure 553b39f9-1e8c-47b1-abf5-8daf7b0391e9; elevation required; cleanup not declared. Not executed or individually validated.
- Disable Bash History Logging with SSH -T
Procedure 5f8abd62-f615-43c5-b6be-f780f25790a1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Clear and Disable Bash History Logging
Procedure 784e4011-bd1a-4ecd-a63a-8feb278512e6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Clear history of a bunch of shells
Procedure 7e6721df-5f08-4370-9255-f06d8a77af4c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Bash history (rm)
Procedure a934276e-2be5-4a36-93fd-98adbb5bd4fc; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Bash history (cat dev/null)
Procedure b1251c35-dcd3-4ea1-86da-36d27b54f31f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Bash history (echo)
Procedure cbf506a5-dd78-43e5-be7e-a46b7c7a0a11; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clear Powershell History by Deleting History File
Procedure da75ae8d-26d6-4483-b0fe-700e4df4f037; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.