---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for User Deleting Bash History - Cloud

# Playbook for User Deleting Bash History - Cloud {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

This playbook provides systematic remediation steps to investigate incidents that indicate if someone was trying to remove the bash history (.bash_history) file from a Linux server.  
Nota:  
You need to mitigate this alert cautiously, as this alerts gets rarely triggered and it potentially indicates an insider threat.
* **[Set up the User Deleting Bash History playbook](https://servicenow-prod.fluidtopics.net/QrpOtVxatAK~C4JbQaBWwg)**   
  Use the following steps to set up the User Deleting Bash History playbook.
* **[Use the User Deleting Bash History playbook](https://servicenow-prod.fluidtopics.net/jlf52hqbYTEuZX~2LNUdxQ)**   
  Use this playbook to investigate incidents that indicate if someone was trying to remove the bash history file from a Linux server. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the User Deleting the Bash History (.bash_history) playbook.

