CAPEC-571: Block Logging to Central Repository
An adversary prevents host-generated logs being delivered to a central location in an attempt to hide indicators of compromise.
Last updated
Overview
In the case of network based reporting of indicators, an adversary may block traffic associated with reporting to prevent central station analysis. This may be accomplished by many means such as stopping a local process to creating a host-based firewall rule to block traffic to a specific server. In the case of local based reporting of indicators, an adversary may block delivery of locally-generated log files themselves to the central repository.
Terminology & mappings
Mapped taxonomies
- ATTACK: Impair Defenses: Disable Windows Event Logging (1562.002)
- ATTACK: Impair Defenses: Impair Command History Logging (1562.002)
- ATTACK: Impair Defenses: Indicator Blocking (1562.006)
- ATTACK: Impair Defenses: Disable Cloud Logs (1562.008)
Frequently asked questions
Common questions about CAPEC-571.
- What is CAPEC-571?
- An adversary prevents host-generated logs being delivered to a central location in an attempt to hide indicators of compromise.
- How severe is CAPEC-571?
- MITRE rates CAPEC-571 as Low severity.
References
Attack-pattern data is sourced from the MITRE CAPEC catalog (v3.9). Weakness associations link to the corresponding CWE entries on RadicalNotion.AI.
Defend against CAPEC-571
Track the CVEs and weaknesses attackers exploit with this technique, with AI-written analysis and remediation guidance.