1200KM / simulation
T1690 Prevent Command History Logging — Attack Simulation
Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they have done. On Linux and macOS, command history is tracked in a file pointed to by the environment variable `HISTFILE`. When a user logs off a system, this information is flushed to a file in the user's home directory called…
Technique description
Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they have done. On Linux and macOS, command history is tracked in a file pointed to by the environment variable `HISTFILE`. When a user logs off a system, this information is flushed to a file in the user's home directory called…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Setting the HISTCONTROL environment variable
Procedure 10ab786a-028e-4465-96f6-9e83ca6c5f24; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Command Line Auditing using reg.exe
Procedure 1329d5ab-e10e-4e5e-93d1-4d907eb656e5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Setting the HISTSIZE environment variable
Procedure 386d3850-2ce7-4508-b56b-c0558922c814; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Mac HISTCONTROL
Procedure 468566d5-83e5-40c1-b338-511e1659628d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Disable history collection
Procedure 4eafdb45-0f79-4d66-aa86-a3e2c08791f5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Setting the HISTFILESIZE environment variable
Procedure 5cafd6c1-2f43-46eb-ac47-a5301ba0a618; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Clear bash history
Procedure 878794f7-c511-4199-a950-8c28b3ed8e5b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Command Line Auditing using Powershell Cmdlet
Procedure 95f5c72f-6dfe-45f3-a8c1-d8faa07176fa; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Setting the HISTFILE environment variable
Procedure b3dacb6c-a9e3-44ec-bf87-38db60c5cad1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable history collection (freebsd)
Procedure cada55b4-8251-4c60-819e-8ec1b33c9306; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Setting the HISTIGNORE environment variable
Procedure f12acddb-7502-4ce6-a146-5b62c59592f1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Setting the HISTFILE environment variable (freebsd)
Procedure f7308845-6da8-468e-99f2-4271f2f5bb67; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.