T1070 - Indicator Removal
Tattiche:
Stealth
Stealth
Piattaforme:
Containers ESXi Linux macOS +3
Containers ESXi Linux macOS +3
Rilevamento:
Not specified
Not specified
Description:
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.
These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.
Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.
These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.
Sub-tecniche (10)
Usato da Attori (4)
Malware (20)
Orz other
Stuxnet other
Sardonic other
Bankshot other
DUSTTRAP other
Neoichor other
BlackEnergy other
Rising Sun other
Flagpro other
DarkWatchman other
MultiLayer Wiper other
EVILNUM other
Metamorfo other
BPFDoor other
SDBbot other
Sibot other
HermeticWiper other
SUNBURST other
IPsec Helper other
FunnyDream other
Metadata
| MITRE ID: | T1070 |
| STIX ID: | attack-pattern--799ace7f-e227-... |
| Piattaforme: | Containers, ESXi, Linux, macOS, Network Devices, Office Suite, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/06/2026 16:00 |