Trusted Design

T1146 - Clear Command History

概要

In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. macOS and Linux both keep track of the commands users type in their terminal so that users can retrace what they've done. These logs can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by the environment variable HISTFILE. When a user logs off a system, this information is flushed to a file in the user's home directory called ~/.bash_history. The benefit of this is that it allows users to go back to commands they've used before in different sessions. Since everything typed on the command-line is saved, passwords passed in on the command line are also saved. Adversaries can abuse this by searching these files for cleartext passwords. Additionally, adversaries can use a variety of methods to prevent their own commands from appear in these logs such as unset HISTFILE, export HISTFILESIZE=0, history -c, rm ~/.bash_history.

管理者によるコメント

MITRE ATT&CKにおいて、T1146は「Clear Command History(コマンド履歴の消去)」として定義されている「防御回避(Defense Evasion)」のテクニックです。

Linux/Unix(Bash, Zsh)やWindows(PowerShell, cmd.exe)などのシェル環境において、攻撃者が実行した不審なコマンド(偵察、横展開、マルウェア実行など)の記録ログ(ヒストリファイル)を意図的に削除・無効化する手法です。

1. 概要(攻撃者は何を実現できるのか?)

この手法で攻撃者は、「侵害後の調査(フォレンジック)を妨害し、自身の手口や使用したコマンド・アクセス先を隠蔽すること」を実現します。

2. 攻撃の流れ

攻撃者はシェルの標準環境変数やコマンドを利用して、履歴の記録を停止するかファイルを消去します。

  1. 侵入と対話型シェルの獲得:
    SSHの不正利用やWebシェル経由でターゲット(主にLinux/Unix環境)にログインします。

  2. コマンド履歴の無効化・削除(T1146の発動):
    攻撃者は以下のようなコマンドを実行します。

    • 履歴ファイルの直接消去:
      rm ~/.bash_history
      history -c

    history -c でメモリ上の履歴をクリアし、rm でファイル自体を削除します。

    • 環境変数による一時的な履歴オフ(事前隠蔽):
      unset HISTFILE
      # または
      export HISTSIZE=0

    セッション開始直後に unset HISTFILE を設定することで、そのセッションで行った全操作が最初からファイルに保存されないようにします。

    • スペースを先頭に付けたコマンド実行(Bashの仕様悪用):
      HISTCONTROL=ignoreboth や ignorespace が設定されている環境では、コマンドの先頭に半角スペースを入れて実行することで、そのコマンドだけを履歴から除外させます。

    • PowerShell(Windows)の場合: Remove-Item (Get-PSReadLineOption).HistorySavePath

  3. 目的の攻撃操作の実行:
    履歴が残らない状態で、権限昇格やデータ持ち出し(Exfiltration)のコマンドを実行します。

3. 防御・対策

ローカルファイルとしてのヒストリだけに依存せず、カーネルレベルや集中ログサーバーへリアルタイム転送する仕組みが不可欠です。

4. 重要ポイント

5. 関連する主なCWE

6. 関連する代表的な事例

実務上のアドバイス:
Linuxのセキュリティ監視において、「unset HISTFILE」「export HISTSIZE=0」「history -c」「rm ~/.bash_history」 の実行(またはプロセス生成)を auditd や SIEM で検知した場合、それは高確率で第三者による侵入・痕跡消去(旧 T1144 / 現 T1070.003)の発生を意味します。

単に「履歴が消された」こと自体を追うだけでなく、カーネルログ(audit.log)やプロキシログから「その直前にどのセッション(IP/Port)からどのユーザー権限でログインされたか」をログサーバー側から即時特定してください。

分析

この攻撃手法を利用する脅威アクター

関連する CVE

攻撃手法 – 脅威アクター Graph


← Technique一覧に戻る ← Tactics一覧に戻る