T1070.004 File Deletion — ATT&CK Technique
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include del on Windows, rm or unlink on Linux and macOS, and `rm` on ESXi.
Detection coverage (30)
- Cisco File Deletion medium
- ADS Zone.Identifier Deleted low
- Use Of Remove-Item to Delete File - ScriptBlock low
- File Deletion informational
- Backup Catalog Deleted medium
- Potential Secure Deletion with SDelete medium
- TeamViewer Log File Deleted low
- Prefetch File Deleted high
- File Deleted Via Sysinternals SDelete medium
- ADS Zone.Identifier Deleted By Uncommon Application medium
- File Deletion Via Del low
- Greedy File Deletion Using Del medium
- Suspicious Ping/Del Command Combination high
- Directory Removal Via Rmdir low
- Potentially Suspicious Ping/Copy Command Combination medium
- Clear Unallocated Sector Using Cipher App
- Linux Account Manipulation Of SSH Config and Keys
- Linux Deletion Of Cron Jobs
- Linux Deletion Of Services
- Linux Deletion Of Init Daemon Script
- Linux Deletion of SSL Certificate
- Linux High Frequency Of File Deletion In Boot Folder
- Linux Indicator Removal Service File Deletion
- Linux High Frequency Of File Deletion In Etc Folder
- Recursive Delete of Directory In Batch CMD
- Sdelete Application Execution
- Windows Default Rdp File Deletion
- Windows RDP Server Registry Deletion
- Windows Rdp AutomaticDestinations Deletion
- Windows RDP Cache File Deletion
Malware using this technique
- PowerDuke
- BLINDINGCAN
- RCSession
- Bumblebee
- BRICKSTORM
- MURKYTOP
- RDFSNIFFER
- NICECURL
- Proxysvc
- NOKKI
- Backdoor.Oldrea
- Stuxnet
- Bandook
- MagicRAT
- VersaMem
- TDTESS
- COATHANGER
- HALFBAKED
- WindTail
- Misdat
- Exaramel for Linux
- HAWKBALL
- Ursnif
- RansomHub
- RedLeaves
- Zeus Panda
- ShimRat
- CARROTBAT
- Bankshot
- StrongPity
- Pony
- Nebulae
- AuditCred
- TONESHELL
- UPSTYLE
- OceanSalt
- Medusa Ransomware
- RainyDay
- AppleSeed
- SQLRat
- PyDCrypt
- GreyEnergy
- Gomir
- Aria-body
- BOLDMOVE
- Crimson
- BADHATCH
- Machete
- Prikormka
- Woody RAT
Threat actors using this technique
- Prinz Eugen
- Crypto24
- Medusa Ransomware
- Play Ransomware
- Termite
- APT38
- BlackByte
- APT3
- Kimsuky
- Volt Typhoon
- APT41
- Dragonfly
- Evilnum
- APT10
- APT32
- FIN6
- Gamaredon Group
- TeamTNT
- Sandworm Team
- APT18
- Mustang Panda
- APT35
- Rocke
- APT39
- UNC3886
- Contagious Interview
- OilRig
- Tropic Trooper
- Aquatic Panda
- The White Company
- Group5
- APT27
- Patchwork
- RedCurl
- FIN5
- APT29
- Chimera
- MirrorFace
- BRONZE BUTLER
- FIN10
- FIN8
- Ember Bear
- APT28
- Metador
- APT5
- Lazarus Group
- INC Ransom
- Silence
- Cobalt Group
- Conti