Engage Goals: EGO0001 Expose, EGO0003 Elicit
Engage Approach: EAP0001 Collect, EAP0002 Detect
Engage Actions: EAC0015 Information Manipulation, EAC0018 Security Controls
Name of Element: Fake Linux System Logs
Description of Element:
Goal: To identify attackers attempting to tamper with or destroy system logs.
Approach: Monitoring access to the fake system logs and analyzing attacker behavior. This element involves creating fake system logs that mimic legitimate logs but contain misleading or deceptive information.
Attackers who attempt to tamper with or destroy the fake system logs will be identified and their actions will be logged. This information can be used to improve defenses and make it more difficult for attackers to cover their tracks.
Technical Context:
This element can be combined with other deceptive elements, such as deceptive configuration files or deceptive network configurations, to enhance its effectiveness. It aligns with the MITRE ATT&CK technique T1070 (Indicator Removal on Host).
Other:
This element requires careful planning and execution to ensure that it does not interfere with the normal operation of the system.