Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF026.002
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Application Log Modification

A subject intentionally alters audit, authentication, access, transaction, or administrative records generated by an organizational application to conceal or misrepresent activity conducted through that application.

 

The subject may change the recorded actor, timestamp, source address, action, affected object, approval state, or result. Modification may be performed through application administration functionality, an Application Programming Interface (API), direct database access, scripts, or access to the underlying log repository.

 

Investigators should compare application records with identity logs, database activity, endpoint telemetry, web proxy records, workflow history, and relevant business records.