StandardDraft
CAPEC-268Audit Log Manipulation
Abstraction
Standard
Status
Draft
Description
The attacker injects, manipulates, deletes, or forges malicious log entries into the log file, in an attempt to mislead an audit of the log file or cover tracks of an attack. Due to either insufficient access controls of the log files or the logging mechanism, the attacker is able to perform such actions.
Related weaknesses· 1
MITRE ATT&CK crosswalk· 4
Related attack patterns· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Output Neutralization for Logscwe-117 | 100% | live |
Related to4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Indicator Removalt1070 | 100% | live |
| SubTechnique | Disable Windows Event Loggingt1562.002 | 100% | live |
| SubTechnique | Disable or Modify Cloud Logst1562.008 | 100% | live |
| SubTechnique | Impair Command History Loggingt1562.003 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.