Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF026.003
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Network and Security Device Log Modification

A subject intentionally alters records generated by network or security infrastructure to conceal, misattribute, or misrepresent network activity.

 

Affected records may include firewall, proxy, Virtual Private Network (VPN), Domain Name System (DNS), Network Access Control (NAC), intrusion detection, router, switch, or secure web gateway logs. The subject may change source or destination addresses, ports, protocols, requested domains, authenticated identities, timestamps, security decisions, or action outcomes.

 

Modification may occur on the originating device, its management controller, a centralized collector, or another downstream repository. Investigators should compare device logs with NetFlow, packet inspection, endpoint telemetry, DNS records, identity events, and independently collected network records.