Sub-technique of T1070 Indicator Removal.View on attack.mitre.org
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include del on Windows, rm or unlink on Linux and macOS, and `rm` on ESXi.
Rules on DetectionCode tagged with T1070.004.
| Rule | Level | Log source |
|---|---|---|
| Prefetch File Deleted | high | windows / file_delete |
| Suspicious Ping/Del Command Combination | high | windows / process_creation |
| ADS Zone.Identifier Deleted By Uncommon Application | medium | windows / file_delete |
| Backup Catalog Deleted | medium | windows / NULL |
| Cisco File Deletion | medium | cisco / NULL |
| File Deleted Via Sysinternals SDelete | medium | windows / file_delete |
| Greedy File Deletion Using Del | medium | windows / process_creation |
| Potential Secure Deletion with SDelete | medium | windows / NULL |
| Potentially Suspicious Ping/Copy Command Combination | medium | windows / process_creation |
| Directory Removal Via Rmdir | low | windows / process_creation |
| File Deletion Via Del | low | windows / process_creation |
| TeamViewer Log File Deleted | low | windows / file_delete |
| File Deletion | informational | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Clear Unallocated Sector Using Cipher App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Linux Account Manipulation Of SSH Config and Keys | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Deletion Of Cron Jobs | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Deletion Of Init Daemon Script | TTP | NULL | Sysmon for Linux EventID 11 |
| Linux Deletion Of Services | TTP | NULL | Sysmon for Linux EventID 11 |
| Linux Deletion of SSL Certificate | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux High Frequency Of File Deletion In Boot Folder | TTP | NULL | Sysmon for Linux EventID 11 |
| Linux High Frequency Of File Deletion In Etc Folder | Anomaly | NULL | Sysmon for Linux EventID 11 |
| Linux Indicator Removal Service File Deletion | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Recursive Delete of Directory In Batch CMD | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Sdelete Application Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Default Rdp File Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 |
| Windows Rdp AutomaticDestinations Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 |
| Windows RDP Cache File Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 |
| Windows RDP Server Registry Deletion | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAPT18 | APT18 actors deleted tools and batch files from victim systems. |
| GroupAPT28 | APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner. |
| GroupAPT29 | APT29 has used SDelete to remove artifacts from victim networks. |
| GroupAPT3 | APT3 has a tool that can delete files. |
| GroupAPT32 | APT32's macOS backdoor can receive a “delete” command. |
| GroupAPT38 | APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
| GroupAPT39 | APT39 has used malware to delete files after they are deployed on a compromised host. |
| GroupAPT41 | APT41 deleted files from the system. |
| Used by | Procedure example |
|---|---|
| MalwareAcidPour | AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory. |
| MalwareADVSTORESHELL | ADVSTORESHELL can delete files and directories. |
| MalwareAnchor | Anchor can self delete its dropper after the malware is successfully deployed. |
| MalwareApostle | Apostle writes batch scripts to disk, such as |
| MalwareAppleJeus | AppleJeus has deleted the MSI file after installation. |
| MalwareAppleSeed | AppleSeed can delete files from a compromised host after they are exfiltrated. |
| MalwareAria-body | Aria-body has the ability to delete files and directories on compromised hosts. |
| MalwareAttor | Attor’s plugin deletes the collected files and log files after exfiltration. |
View all 251 software examples
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, vba_macro.exe deletes itself after `FONTCACHE.DAT`, `rundll32.exe`, and the associated .lnk file is delivered. |
| CampaignAPT41 DUST | APT41 DUST deleted various artifacts from victim systems following use. |
| CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them. |
| CampaignCutting Edge | During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files. |
| CampaignKV Botnet Activity | KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.