CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has gained root access on a Linux server and wants to ensure that all traces of their activity are removed. This includes shell history, temporary files, and log entries. Which of the following cleanup actions is MOST critical to prevent detection and forensic analysis?

  1. AClearing shell history files for all users.
  2. BModifying or deleting relevant entries in `/var/log`.
  3. CDeleting all files in `/tmp` and `/var/tmp`.
  4. DRestoring original binaries if any were modified or replaced.
Show answer & explanation

Correct answer: B. Modifying or deleting relevant entries in `/var/log`.

Modifying or deleting relevant log entries in `/var/log` (e.g., `auth.log`, `syslog`, `history.log`) is the most critical cleanup action. Log files provide a chronological record of system events, user activities, and network connections. Tampering with or removing these entries is paramount to hindering forensic analysis and preventing detection of the attacker's presence and actions.

Why the other options are wrong

  • A. Clearing shell history is important for user-specific activity, but system-wide logs provide broader evidence.
  • C. Deleting temporary files is important but less critical than logs, as logs contain direct evidence of actions.
  • D. Restoring binaries is important for system integrity but focuses on preventing detection of specific backdoors rather than overall activity traces.

Log File Cleanup (Linux)

The process of identifying and removing or modifying specific entries in system log files (e.g., `/var/log/*`) to erase traces of attacker activity and prevent forensic analysis.

  • Crucial for evading detection and hindering incident response.
  • Requires root privileges to access and modify system logs.
  • Can involve tools like `logrotate` manipulation, `zap` (for specific entries), or direct file editing.

Memory trick: Logs are the memory, erase them all.

More Post-exploitation and Lateral Movement questions