CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has successfully escalated privileges to root on a Linux server. To ensure all traces of the compromise are removed and to avoid detection, the tester needs to clean up logs and temporary files. Which directory would be LEAST likely to contain evidence of the compromise that needs manual cleanup?
- A/usr/bin/
- B/var/log/
- C/root/.bash_history
- D/tmp/
Show answer & explanationAnswer & explanation
Correct answer: A. /usr/bin/
/usr/bin/ is a directory for essential user command binaries. While an attacker might place a malicious binary here, it's a highly visible location and not primarily used for storing temporary files, logs, or command history, making it less likely to contain 'evidence of compromise' that needs cleanup in the sense of logs or temp files.
Why the other options are wrong
- B. /var/log/ contains system logs (auth.log, syslog, etc.) which are critical for detecting compromise and require cleanup.
- C. /root/.bash_history stores commands executed by the root user, which would directly show attacker activity and needs to be cleared.
- D. /tmp/ is a common location for temporary files, including those left by attackers, and often needs cleanup.
Post-Exploitation Cleanup
The process of removing all traces of a penetration test or compromise from a system, including logs, temporary files, created accounts, and deployed tools.
- Crucial for avoiding detection and maintaining stealth.
- Involves clearing command histories, system logs, and temporary directories.
- Also includes removing any persistence mechanisms or backdoors.
Memory trick: To clean Linux, sweep the logs, history, and temp, but not the core bins.