Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · stealth

T1070 Indicator Removal

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior. Artifacts such as command…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 42.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.