Anti-Forensic Technique
Definition
Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use of encrypted channels, and deployment of rootkits.
- Purpose
- Destroy, conceal, or alter evidence of activity
- Examples
- Log clearing, timestomping, encrypted channels, rootkits
- Used by
- Attackers in unauthorised access cases
- Field
- Digital forensics, cybercrime investigation
Common questions
Why does timestomping create a problem for investigators beyond just hiding one file?+
Timestomping alters file metadata such as creation or modification times to blend malicious files into normal system activity or disrupt a timeline reconstruction, which can mislead an entire incident timeline rather than just concealing a single artefact.
Can log clearing ever be fully undone by an investigator?+
Not always. Some logs can be partially recovered from backups, remote log aggregation, or unallocated disk space, but a thoroughly cleared and overwritten local log may leave no recoverable trace, which is why centralised, off-host logging is a recommended defence.
Related terms
- Credential Stuffing
- An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Living-Off-the-Land (LotL)
- An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
- Privilege Escalation
- A post-access technique in which an attacker who has gained low-level access to a system exploits a vulnerability or misconfiguration to obtain...
- Unauthorised Access
- The act of accessing a computer, network, or data store without permission from the owner or without lawful authority. The core element...