T1070 Indicator Removal — ATT&CK Technique
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior. Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion. These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.
Detection coverage (28)
- Kubernetes Events Deleted medium
- SES Identity Has Been Deleted medium
- Linux Package Uninstall low
- Remove Exported Mailbox from Exchange Webserver high
- PowerShell Console History Logs Deleted medium
- EventLog EVTX File Deleted medium
- IIS WebServer Access Logs Deleted medium
- Exchange PowerShell Cmdlet History Deleted high
- Tomcat WebServer Logs Deleted medium
- DLL Load By System Process From Suspicious Locations medium
- Clearing Windows Console History high
- Disable of ETW Trace - Powershell high
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE medium
- Fsutil Suspicious Invocation high
- Sysmon Driver Unloaded Via Fltmc.EXE high
- Filter Driver Unloaded Via Fltmc.EXE medium
- IIS WebServer Log Deletion via CommandLine Utilities medium
- ETW Trace Evasion Activity high
- Shadow Copies Deletion Using Operating Systems Utilities high
- Terminal Server Client Connection History Cleared - Registry high
- Cisco ASA - Logging Message Suppression
- ESXi Audit Tampering
- Fsutil Zeroing File
- Linux Indicator Removal Clear Cache
- MacOS Log Removal
- Process Deleting Its Process File Path
- USN Journal Deletion
- Windows Indicator Removal Via Rmdir
Malware using this technique
- IPsec Helper
- Donut
- SDBbot
- BPFDoor
- ShadowPad
- BlackEnergy
- EVILNUM
- SILENTTRINITY
- MultiLayer Wiper
- Orz
- DUSTTRAP
- HermeticWiper
- Metamorfo
- Stuxnet
- Rising Sun
- Flagpro
- Remcos
- FunnyDream
- Sardonic
- Maze
- Sibot
- CSPY Downloader
- Bankshot
- IronWind
- DarkWatchman
- SUNBURST
- Neoichor