Technique with 8 sub-techniques.View on attack.mitre.org
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.
These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.
Rules on DetectionCode tagged with T1070 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco ASA - Logging Message Suppression | Anomaly | NULL | Cisco ASA Logs | T1070 |
| Cisco ASA - User Account Deleted From Local Database | Anomaly | NULL | Cisco ASA Logs | T1070.008 |
| Clear Unallocated Sector Using Cipher App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070.004 |
| Create or delete windows shares using net exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070.005 |
| ESXi Audit Tampering | TTP | NULL | VMWare ESXi Syslog | T1070 |
| ESXi System Clock Manipulation | TTP | NULL | VMWare ESXi Syslog | T1070.006 |
| Fsutil Zeroing File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070 |
| Linux Account Manipulation Of SSH Config and Keys | Anomaly | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux Deletion Of Cron Jobs | Anomaly | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux Deletion Of Init Daemon Script | TTP | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux Deletion Of Services | TTP | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux Deletion of SSL Certificate | Anomaly | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux High Frequency Of File Deletion In Boot Folder | TTP | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux High Frequency Of File Deletion In Etc Folder | Anomaly | NULL | Sysmon for Linux EventID 11 | T1070.004 |
| Linux Indicator Removal Clear Cache | TTP | NULL | Sysmon for Linux EventID 1 | T1070 |
| Linux Indicator Removal Service File Deletion | Anomaly | NULL | Sysmon for Linux EventID 1 | T1070.004 |
| MacOS Log Removal | TTP | NULL | Osquery Results | T1070 |
| O365 Email Hard Delete Excessive Volume | Anomaly | NULL | Office 365 Universal Audit Log | T1070.008 |
| O365 Email Password and Payroll Compromise Behavior | TTP | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace | T1070.008 |
| O365 Email Receive and Hard Delete Takeover Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace | T1070.008 |
| O365 Email Send and Hard Delete Exfiltration Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace | T1070.008 |
| O365 Email Send and Hard Delete Suspicious Behavior | Anomaly | NULL | Office 365 Universal Audit Log | T1070.008 |
| O365 Email Send Attachments Excessive Volume | Anomaly | NULL | Office 365 Universal Audit Log | T1070.008 |
| Process Deleting Its Process File Path | TTP | NULL | Sysmon EventID 1 | T1070 |
| Recursive Delete of Directory In Batch CMD | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070.004 |
| Sdelete Application Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070.004 |
| USN Journal Deletion | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070 |
| Windows ConsoleHost History File Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 | T1070.003 |
| Windows Default Rdp File Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 | T1070.004 |
| Windows Indicator Removal Via Rmdir | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1070 |
| Windows Powershell History File Deletion | Anomaly | NULL | Powershell Script Block Logging 4104 | T1070.003 |
| Windows Rdp AutomaticDestinations Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 | T1070.004 |
| Windows RDP Cache File Deletion | Anomaly | NULL | Sysmon EventID 23, Sysmon EventID 26 | T1070.004 |
| Windows RDP Server Registry Deletion | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 | T1070.004 |
| Used by | Procedure example |
|---|---|
| GroupAPT42 | APT42 has cleared Chrome browser history. |
| GroupAPT5 | APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| GroupLazarus Group | Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked. |
| GroupMustang Panda | Mustang Panda has deleted registry keys that store data and maintained persistence. |
| Used by | Procedure example |
|---|---|
| MalwareBankshot | Bankshot deletes all artifacts associated with the malware from the infected machine. |
| MalwareBlackEnergy | BlackEnergy has removed the watermark associated with enabling the |
| MalwareBPFDoor | BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process. |
| ToolCSPY Downloader | CSPY Downloader has the ability to remove values it writes to the Registry. |
| MalwareDarkWatchman | DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history. |
| ToolDonut | Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
| MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| MalwareEVILNUM | EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| Used by | Procedure example |
|---|---|
| CampaignCutting Edge | During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.