// soc investigation 2026-08-05
SOC306 Critical System File Deletion
letsdefend Medium ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1033mitre/T1069mitre/T1083mitre/T1548-003mitre/T1070-002
analyst verdict TRUE POSITIVE
✓

🔍 What

An external attacker brute-forced SSH credentials for the analyst account on host Dominic. After gaining access, the attacker performed system reconnaissance, escalated privileges to root via unrestricted sudo rights, created a backdoor local account (lettsdefend), and deleted auth.log and audit.rules to destroy forensic evidence.


🕐 When

EventTimestamp
Brute-force activity (pre-login)Prior to Jul 31, 2024, 03:10 PM
Successful SSH login (analyst)Jul 31, 2024, 03:10 PM
audit.rules deleted (alert trigger)Jul 31, 2024, 03:14 PM

📍 Where


👤 Who


❓ Why

The analyst account held unrestricted sudo rights, giving the attacker a direct path to root-level access without needing to exploit a vulnerability. This privilege level allowed the creation of a new local persistence account and the removal of both authentication and audit logs to hinder investigation.

Attacker command sequence (bash_history):

whoami
groups
cat /etc/group
find / -type f -name '*password*'
sudo useradd -m lettsdefend
sudo passwd lettsdefend
cd /var/log
cat auth.log | grep "87.249.134.136"
rm -r auth.log
cd /etc/audit/rules.d/
ls
cat audit.rules
rm -r audit.rules

🎯 MITRE ATT&CK

Technique IDTacticTechnique
T1110.001Credential AccessBrute Force - Password Guessing
T1078Initial AccessValid Accounts
T1033DiscoverySystem Owner/User Discovery
T1069DiscoveryPermission Groups Discovery
T1083DiscoveryFile and Directory Discovery
T1548.003Privilege EscalationAbuse Elevation Control Mechanism - Sudo
T1136.001PersistenceCreate Account - Local Account
T1070.002Defense EvasionIndicator Removal - Clear Linux or Mac System Logs

🧩 IOCs

TypeValueNotes
IP Address87[.]249[.]134[.]136Attacker — AbuseIPDB: malicious, brute force/SSH
IP Address172[.]16[.]17[.]107Victim host — Dominic
UsernameanalystCompromised account
UsernamelettsdefendBackdoor account created by attacker
File/var/log/auth[.]logDeleted by attacker
File/etc/audit/rules[.]d/audit[.]rulesDeleted by attacker (alert trigger)

🔗 Analysis Reports