Gaps in log files and deleted evidence can signal that an attacker has compromised a system and attempted to cover their tracks. Identifying these anomalies is a critical step in incident detection and response.
Covering Tracks via Log Deletion
Another thing that an adversary could be doing to cover their tracks is delete log files and remove other evidence. So that's another sign that we're going to be looking for, to see if there's any compromise or an attack on our system.
So for our example here, we're going to say that there's some logs that are being performed on some sort of device here. There's a security service check that's performed, and it flags whether there's concerns or no concerns, and we can see that it's doing it every minute, or every second actually. So every second it's happening, and then here we suddenly have a five minute gap, a more than a five minute gap.
So something happened here, but what happened? What was the anomaly caused by? Did somebody do a restart on the server? Did somebody turn the application off for a little bit? Or maybe somebody was trying to perform a hack on the system, did compromise the system, did the attack on it, and then covered their evidence by going in and deleting these logs. And so now we need to further research into this to figure out what happened on the system. So this could be an indicator of a compromise when there's removed evidence.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →