← All episodes

Your logs are useless if an attacker can delete them

September 8, 2026
Your logs are useless if an attacker can delete them Watch on YouTube

You also need to protect where logs are stored. If an attacker gains local administrative privileges, having the log on the same disk is not enough. Correct. Auditd helps detect tampering and leaves traces of many changes, but an adversary with sufficient control can try to manipulate

You also need to protect where logs are stored. If an attacker gains local administrative privileges, having the log on the same disk is not enough. Correct. Auditd helps detect tampering and leaves traces of many changes, but an adversary with sufficient control can try to manipulate logs, rules, or storage. A mature practice is to send events to a remote system with access controls, retention, and alerts that are independent of the server being monitored. This is not because the remote destination is invulnerable, but because it forces an attacker to compromise more than one component and allows evidence to be preserved outside the affected machine.

Full episode: https://youtu.be/DgszZ6KV1ok

🤖 AI-generated content: the script, voices, and images for this episode were produced using artificial intelligence tools.

#Shorts

Enjoyed the episode? Buy me a coffee ☕