Playbook for User Deleting Bash History - Cloud
This playbook provides systematic remediation steps to investigate incidents that indicate if someone was trying to remove the bash history (.bash_history) file from a Linux server.
Note: You need to mitigate this alert cautiously, as this alerts gets rarely triggered and it potentially indicates an insider threat.
- Set up the User Deleting Bash History playbook
Use the following steps to set up the User Deleting Bash History playbook. - Use the User Deleting Bash History playbook
Use this playbook to investigate incidents that indicate if someone was trying to remove the bash history file from a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the User Deleting the Bash History (.bash_history) playbook.
Parent Topic:Flow-based Playbooks