Adversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection.

Tactics
TA0005

Sub-technique of
T1562


See: MITRE ATT&CK