// MITRE ATT&CK
T1070 · Indicator Removal
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving suffici...
How to detect & mitigate it
Detecting Indicator Removal starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1070.003
Clear Command History T1070.004
File Deletion T1070.005
Network Share Connection Removal T1070.006
Timestomp T1070.007
Clear Network Connection History and Configurations T1070.008
Clear Mailbox Data T1070.009
Clear Persistence T1070.010
Relocate Malware
Clear Command History T1070.004
File Deletion T1070.005
Network Share Connection Removal T1070.006
Timestomp T1070.007
Clear Network Connection History and Configurations T1070.008
Clear Mailbox Data T1070.009
Clear Persistence T1070.010
Relocate Malware
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.