Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Playbook for User Deleting Bash History - Cloud

This playbook provides systematic remediation steps to investigate incidents that indicate if someone was trying to remove the bash history (.bash_history) file from a Linux server.

Note: You need to mitigate this alert cautiously, as this alerts gets rarely triggered and it potentially indicates an insider threat.

  • Set up the User Deleting Bash History playbook
    Use the following steps to set up the User Deleting Bash History playbook.
  • Use the User Deleting Bash History playbook
    Use this playbook to investigate incidents that indicate if someone was trying to remove the bash history file from a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the User Deleting the Bash History (.bash_history) playbook.

Parent Topic:Flow-based Playbooks