T1070 Indicator Removal
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior. Artifacts such as command…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Fsutil Suspicious Invocationhighstable · windows
- Shadow Copies Deletion Using Operating Systems Utilitieshighstable · windows
- Cisco Clear Logshightest · cisco
- Clearing Windows Console Historyhightest · windows
- Disable Powershell Command Historyhightest · windows
- Disable of ETW Trace - Powershellhightest · windows
- ETW Trace Evasion Activityhightest · windows
- Exchange PowerShell Cmdlet History Deletedhightest · windows
- Linux Command History Tamperinghightest · linux
- Prefetch File Deletedhightest · windows
- Remove Exported Mailbox from Exchange Webserverhightest · windows
- Suspicious Ping/Del Command Combinationhightest · windows
- Sysmon Driver Unloaded Via Fltmc.EXEhightest · windows
- Terminal Server Client Connection History Cleared - Registryhightest · windows
- RunMRU Registry Key Deletionhighexperimental · windows
- RunMRU Registry Key Deletion - Registryhighexperimental · windows
- ADS Zone.Identifier Deleted By Uncommon Applicationmediumtest · windows
- Backup Catalog Deletedmediumtest · windows
- Cisco File Deletionmediumtest · cisco
- Clear PowerShell History - PowerShellmediumtest · windows
- Clear PowerShell History - PowerShell Modulemediumtest · windows
- DLL Load By System Process From Suspicious Locationsmediumtest · windows
- Disable Administrative Share Creation at Startupmediumtest · windows
- EventLog EVTX File Deletedmediumtest · windows
- File Deleted Via Sysinternals SDeletemediumtest · windows
Showing 25 of 42.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.