{"id":"T1690","name":"Prevent Command History Logging","url":"https://attack.mitre.org/techniques/T1690","tactics":["defense-impairment"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0563","stix_id":"x-mitre-detection-strategy--8577b89d-01e2-4423-8657-caff7ed22737","name":"Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.","url":"https://attack.mitre.org/detectionstrategies/DET0563","analytics":[{"id":"AN1555","stix_id":"x-mitre-analytic--1f69e126-e849-43a1-9fca-b5c63a154daa","name":"Analytic 1555","description":"Detection of environment variable tampering (HISTFILE, HISTCONTROL, HISTFILESIZE) and absence of expected bash history writes. Correlation of unset or zeroed history variables with active shell sessions is indicative of adversarial evasion.","url":"https://attack.mitre.org/detectionstrategies/DET0563#AN1555","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve calls modifying HISTFILE or HISTCONTROL via unset/export","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"processes modifying environment variables related to history logging","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"MonitoredUsers","description":"Specific accounts or groups where history logging must always be enforced."},{"field":"TimeWindow","description":"Correlation period to detect unset/export of history variables during active shells."}],"live":true,"detection_strategies":["DET0563"],"techniques":["T1690"]},{"id":"AN1556","stix_id":"x-mitre-analytic--2a5f1993-7035-4d94-b9d1-7edb1850d4e1","name":"Analytic 1556","description":"Detection of bash/zsh history suppression via HISTFILE/HISTCONTROL manipulation and absence of ~/.bash_history updates. Observing environment variable changes tied to terminal processes is a strong indicator.","url":"https://attack.mitre.org/detectionstrategies/DET0563#AN1556","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Set or unset HIST* variables in shell environment","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ShellProfiles","description":"Different shells (bash, zsh, fish) may require customized monitoring for history tampering."}],"live":true,"detection_strategies":["DET0563"],"techniques":["T1690"]},{"id":"AN1557","stix_id":"x-mitre-analytic--91870bc8-3a81-4d90-84e4-26c99b5642ef","name":"Analytic 1557","description":"Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0563#AN1557","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedPaths","description":"List of acceptable PowerShell history save paths for baseline comparison."}],"live":true,"detection_strategies":["DET0563"],"techniques":["T1690"]},{"id":"AN1558","stix_id":"x-mitre-analytic--8ed1a27f-3a60-441d-b92d-dc7b086db459","name":"Analytic 1558","description":"Detection of unset HISTFILE or modified history variables in ESXi shell sessions. Correlation of suspicious shell sessions with no recorded commands despite active usage.","url":"https://attack.mitre.org/detectionstrategies/DET0563#AN1558","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"unset HISTFILE or HISTFILESIZE modifications","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"AdminSessions","description":"Differentiate root/admin shell sessions from adversarial misuse of ESXi shell."}],"live":true,"detection_strategies":["DET0563"],"techniques":["T1690"]},{"id":"AN1559","stix_id":"x-mitre-analytic--77450309-6789-4025-9817-d908c4ac9e5b","name":"Analytic 1559","description":"Detection of CLI commands that disable history logging such as 'no logging'. Anomalous lack of new commands in session logs while activity persists is a strong signal.","url":"https://attack.mitre.org/detectionstrategies/DET0563#AN1559","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"Commands like 'no logging' or equivalents that disable session history","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"DeviceVendors","description":"Command syntax differs across Cisco, Juniper, Fortinet, etc., requiring vendor-aware tuning."}],"live":true,"detection_strategies":["DET0563"],"techniques":["T1690"]}],"live":true,"version":"1.0","techniques":["T1690"]}],"sigma_rules":[{"id":"38eb1dbb-011f-40b1-a126-cf03a0210563","title":"ESXi Syslog Configuration Change Via ESXCLI","author":"Cedric Maurugeon","status":"test","level":"medium","date":"2023-09-04","modified":null,"description":"Detects changes to the ESXi syslog configuration via \"esxcli\"","references":["https://support.solarwinds.com/SuccessCenter/s/article/Configure-ESXi-Syslog-to-LEM?language=en_US","https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_system.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1685","attack.t1690","attack.t1059.012"],"path":"rules/linux/process_creation/proc_creation_lnx_esxcli_syslog_config_change.yml","techniques":["T1685","T1690","T1059.012"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}