Techniques
Sample rules
ESXi Host Logs Deleted with rm
- source: elastic
- technicques:
- T1070
Description
Detects a shell rm of a path under /var/log or of a *.log name. Those files hold shell commands,
authentication, and hostd activity. Removing them takes away the record of what changed on the host.
Detection logic
data_stream.dataset:vsphere.log and event.module:vsphere and message:(rm and ("*.log" or "/var/log/*"))