malware and threat actors may manipulate the HISTFILE environment variable as an anti-analysis, anti-forensics, or evasion technique to prevent their commands from being logged in the shell’s history file.
unset HISTFILE
0001-01-01
Recent Posts
Linux Persistence: Startup Scripts
2024-11-10 DFIR CTF linux persistence systemd SysV init startup script
Linux Persistence: Cron
2024-11-10 DFIR CTF linux persistence cron