T1070.004 File Deletion
Sub-technique of T1070 Indicator Removal
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Prefetch File Deletedhightest · windows
- Suspicious Ping/Del Command Combinationhightest · windows
- ADS Zone.Identifier Deleted By Uncommon Applicationmediumtest · windows
- Backup Catalog Deletedmediumtest · windows
- Cisco File Deletionmediumtest · cisco
- File Deleted Via Sysinternals SDeletemediumtest · windows
- Greedy File Deletion Using Delmediumtest · windows
- Potential Secure Deletion with SDeletemediumtest · windows
- Potentially Suspicious Ping/Copy Command Combinationmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.