# Command Line History (:)
Records commands typed in Vim’s command mode. Analysts will see routine commands like :wq (save and quit) or :set paste.
Red Flag: Look for shell escapes like :!/bin/bash or :!curl. Attackers frequently use Vim to spawn interactive root shells (a classic GTFOBins technique) to bypass restricted environments.