Indicator Removal

T1070

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.

These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.

Detection rules85

Rules on DetectionCode tagged with T1070 or one of its sub-techniques.

Sigma51

RuleLevelLog sourceTechnique
Cisco Clear Logshighcisco / NULLT1070.003
Clearing Windows Console Historyhighwindows / ps_scriptT1070 T1070.003
Disable of ETW Trace - Powershellhighwindows / ps_scriptT1070
Disable Powershell Command Historyhighwindows / ps_scriptT1070.003
ETW Trace Evasion Activityhighwindows / process_creationT1070
Exchange PowerShell Cmdlet History Deletedhighwindows / file_deleteT1070
File Creation Date Changed to Another Yearhighwindows / file_changeT1070.006
Fsutil Suspicious Invocationhighwindows / process_creationT1070
Linux Command History Tamperinghighlinux / NULLT1070.003
Prefetch File Deletedhighwindows / file_deleteT1070.004
Remove Exported Mailbox from Exchange Webserverhighwindows / NULLT1070
RunMRU Registry Key Deletionhighwindows / process_creationT1070.003
RunMRU Registry Key Deletion - Registryhighwindows / registry_deleteT1070.003
Shadow Copies Deletion Using Operating Systems Utilitieshighwindows / process_creationT1070
Suspicious Ping/Del Command Combinationhighwindows / process_creationT1070.004

Splunk34

RuleTypeRiskData sourceTechnique
Cisco ASA - Logging Message SuppressionAnomalyNULLCisco ASA LogsT1070
Cisco ASA - User Account Deleted From Local DatabaseAnomalyNULLCisco ASA LogsT1070.008
Clear Unallocated Sector Using Cipher AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1070.004
Create or delete windows shares using net exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1070.005
ESXi Audit TamperingTTPNULLVMWare ESXi SyslogT1070
ESXi System Clock ManipulationTTPNULLVMWare ESXi SyslogT1070.006
Fsutil Zeroing FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1070
Linux Account Manipulation Of SSH Config and KeysAnomalyNULLSysmon for Linux EventID 11T1070.004
Linux Deletion Of Cron JobsAnomalyNULLSysmon for Linux EventID 11T1070.004
Linux Deletion Of Init Daemon ScriptTTPNULLSysmon for Linux EventID 11T1070.004
Linux Deletion Of ServicesTTPNULLSysmon for Linux EventID 11T1070.004
Linux Deletion of SSL CertificateAnomalyNULLSysmon for Linux EventID 11T1070.004
Linux High Frequency Of File Deletion In Boot FolderTTPNULLSysmon for Linux EventID 11T1070.004
Linux High Frequency Of File Deletion In Etc FolderAnomalyNULLSysmon for Linux EventID 11T1070.004
Linux Indicator Removal Clear CacheTTPNULLSysmon for Linux EventID 1T1070

Sub-techniques8

IDNameExamples
T1070.003Clear Command History11
T1070.004File Deletion311
T1070.005Network Share Connection Removal5
T1070.006Timestomp58
T1070.007Clear Network Connection History and Configurations4
T1070.008Clear Mailbox Data5
T1070.009Clear Persistence15
T1070.010Relocate Malware1

Groups4

Software27

Show 3 more

Campaigns2

Procedure examples33

Groups4

Used byProcedure example
GroupAPT42

APT42 has cleared Chrome browser history.

GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

GroupLazarus Group

Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked.

GroupMustang Panda

Mustang Panda has deleted registry keys that store data and maintained persistence.

Software27

Used byProcedure example
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

MalwareBlackEnergy

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

MalwareBPFDoor

BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process.

ToolCSPY Downloader

CSPY Downloader has the ability to remove values it writes to the Registry.

MalwareDarkWatchman

DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.

ToolDonut

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

MalwareEVILNUM

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

View all 27 software examples

Campaigns2

Used byProcedure example
CampaignCutting Edge

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.