Indicator Removal T1070

Tactic: Stealth

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Events covered

30 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 203 rules share fields, values, and exclusions.

Fields filtered most (117 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine40contains 31, regex_match 7, ends_with 4, in 2 -n , del, (?i)\s(execcmd|runinteractive(cmd)?|savescreenshot(full|w..., -r, .service
TargetFilename40starts_with 15, ends_with 12, wildcard 9, contains 6, in 6.log, /dev/shm/*, /etc/, /etc/ssl/certs/, /home/*/*
event.type39eq 39, in 1start, deletion, change, group, user
process_name39eq 25, in 9, starts_with 6, regex_match 2, ends_with 1bash, powershell.exe, ., busybox, cmd.exe
EventType38eq 29, in 11exec, deletion, exec_event, ProcessRollup2, creation
Image36ends_with 23, starts_with 8, eq 4, is_not_null 3, wildcard 2\cmd.exe, /dev/shm/, ./, /boot/, /rm
host.os.type21eq 21
OriginalFileName20eq 19, in 3cmd.exe, powershell.exe, powershell_ise.exe, pwsh.dll, fltmc.exe
process.args20eq 8, in 7, starts_with 6, wildcard 6, contains 3, regex_match 1+o, --clear, --read-clear, -c, -s0
EventID16eq 12, in 423, 26, 4104, 1102, 4103
ScriptBlockText14contains 13, ends_with 1, eq 1, match 1(get-psreadlineoption).historysavepath, clear-eventlog, -adjust, -date, -historysavestyle
sourcetype13eq 11, in 6o365:management:activity, ms:o365:reporting:messagetrace, o365:reporting:messagetrace, bash_history, cisco:asa
EventId10in 6, eq 41003, 1026, 1028, 1029, 1040
file.extension8eq 5, in 2, is_null 1dll, js, py, crt, exe
event_action7eq 7deleted

Top indicator values (1054 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
281078
event.typeeq
deletion
1216
EventTypeeq
exec
17576
EventTypeeq
deletion
1012
EventTypein
exec
7201
EventTypein
start
6163
EventTypein
exec_event
5149
EventTypein
executed
598
EventTypein
process_started
583
EventTypein
ProcessRollup2
4117
OriginalFileNameeq
cmd.exe
781
event_actioneq
deleted
78
Workloadeq
exchange
620
sourcetypeeq
o365:management:activity
680
Imageends_with
\cmd.exe
5130
process_namein
bash
5202
process_namein
csh
4159
process_namein
fish
4163
CommandLinecontains
del
45
EventIDeq
4104
4269
EventIDin
23
410
EventIDin
26
410
Imagestarts_with
/dev/shm/
453
Imagestarts_with
/tmp/
458
Imagestarts_with
/var/tmp/
456
Operationeq
harddelete
44
event.outcomeeq
success
4369
m365::Folder.Pathin
\\recoverable items\\deletions
44
m365::Folder.Pathin
\\sent items
44
process_nameeq
powershell.exe
4184

Exclusions (399 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinein
/bin/touch -a /tmp/au_status
2
CommandLinein
touch -d 2 seconds ago /etc/postfix/main.cf
2
CurrentDirectoryin
/opt/libexec
2
CurrentDirectoryin
/opt/local/src/connectxx/build/src/mdp
2
Imageeq
/actions-runner/externals/node24/bin/node
2
Imagein
/usr/bin/podman
2
Imagestarts_with
c:\program files (x86)\
2
Imagestarts_with
c:\program files\
2
Imagestarts_with
c:\windows\system32\
2
Imagewildcard
?:\windows\system32\msiexec.exe
2
Imagewildcard
?:\windows\syswow64\msiexec.exe
2
ParentCommandLineeq
runc init
2
ParentImageeq
/tmp/newroot/usr/bin/sudo
2
ParentImagein
/bin/dracut
2
ParentImagein
/bin/ssm-agent-worker
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 64 rules

Elastic 53 rules

Splunk 46 rules

Kusto 30 rules

YARA-L 1 rule

Panther 9 rules