Indicator Removal T1070
Tactic: Stealth
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Events covered
30 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 203 rules share fields, values, and exclusions.
Fields filtered most (117 distinct)
These fields appear most often in rule filters.
Top indicator values (1054 distinct)
These values appear most often in rule predicates.
Exclusions (399 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 64 rules
- Access To Windows Outlook Mail Files By Uncommon Applications
- ADS Zone.Identifier Deleted
- ADS Zone.Identifier Deleted By Uncommon Application
- Backup Catalog Deleted
- Cisco Clear Logs
- Cisco File Deletion
- Clear PowerShell History - PowerShell
- Clear PowerShell History - PowerShell Module
- Clearing Windows Console History
- Directory Removal Via Rmdir
- Disable Administrative Share Creation at Startup
- Disable of ETW Trace - Powershell
- Disable Powershell Command History
- DLL Load By System Process From Suspicious Locations
- ETW Trace Evasion Activity
- Event log clear attempt (command)
- Event log clear attempt (PowerShell)
- Event log clear attempt (wmi)
- Event log cleared (native)
- Event log cleared using Diagnostics (via PowerShell)
- EventLog EVTX File Deleted
- Exchange PowerShell Cmdlet History Deleted
- File Creation Date Changed to Another Year
- File Deleted Via Sysinternals SDelete
- File Deletion
- File Deletion Via Del
- File Time Attribute Change
- File Time Attribute Change - Linux
- Filter Driver Unloaded Via Fltmc.EXE
- Fsutil Suspicious Invocation
- Greedy File Deletion Using Del
- IIS WebServer Access Logs Deleted
- IIS WebServer Log Deletion via CommandLine Utilities
- Kubernetes Events Deleted
- Linux Command History Tampering
- Linux Package Uninstall
- macOS Data Destruction Tools
- macOS ESF Deletion In Sensitive Directories
- MaxMpxCt Registry Value Changed
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
- Potential Secure Deletion with SDelete
- Potentially Suspicious Ping/Copy Command Combination
- PowerShell Console History Logs Deleted
- PowerShell Deleted Mounted Share
- Powershell Timestomp
- Prefetch File Deleted
- Remove Exported Mailbox from Exchange Webserver
- RunMRU Registry Key Deletion
- RunMRU Registry Key Deletion - Registry
- SES Identity Has Been Deleted
- Shadow Copies Deletion Using Operating Systems Utilities
- Suspicious IO.FileStream
- Suspicious Ping/Del Command Combination
- Sysmon Driver Unloaded Via Fltmc.EXE
- System time changed
- System time changed (PowerShell)
- TeamViewer Log File Deleted
- Terminal Server Client Connection History Cleared - Registry
- Tomcat WebServer Logs Deleted
- Touch Suspicious Service File
- Unauthorized System Time Modification
- Unmount Share Via Net.EXE
- Use Of Remove-Item to Delete File - ScriptBlock
- Windows Mail App Mailbox Access Via PowerShell Script
Elastic 53 rules
- Attempt to Clear Kernel Ring Buffer
- Attempt to Clear Kernel Ring Buffer via Dmesg
- Attempt to Clear Logs via Journalctl
- Attempt to Clear Logs via Journalctl
- AWS S3 Bucket Configuration Deletion
- AWS S3 Bucket Expiration Lifecycle Configuration Added
- Azure AKS Kubernetes Events Deleted
- Clearing of Shell History via Environment Variables
- Clearing Windows Console History
- Clearing Windows Event Logs
- Delete Volume USN Journal with Fsutil
- Deletion of Shell History File
- Disable Windows Event and Security Logs Using Built-in Tools
- ESXI Timestomping using Touch Command
- File Creation in /var/log via Suspicious Process
- File Creation, Execution and Self-Deletion in Suspicious Directory
- File Deletion via Shred
- File or Directory Deletion Command
- Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
- Kubernetes Events Deleted
- Linux User or Group Deletion
- Loadable Kernel Module Load Followed by Log Clearing
- M365 Exchange MFA Notification Email Deleted or Moved
- Multiple System Log Files Deletion
- Node Script Execution and Immediate Deletion
- Node Script Execution and Immediate Deletion
- Potential Image Load with a Spoofed Creation Time
- Potential REMCOS Trojan Execution
- Potential Secure File Deletion via SDelete Utility
- Potential Self Deletion of a Running Executable
- Potential Timestomp in Executable Files
- PowerShell Script with Log Clear Capabilities
- Process Execution Followed by Self-Deletion
- Python Library Load and Delete
- Self-Deleted Python Script Outbound Network Connection
- Self-Deleting Python Script
- Sensitive Audit Policy Sub-Category Disabled
- Shell Command-Line History Deletion Detected via Defend for Containers
- Shell History Clearing via Environment Variables
- SSH Authorized Keys File Deletion
- SSH Authorized Keys File Deletion
- SSL Certificate Deletion
- Suspicious PowerShell Console History Deletion
- Suspicious Print Spooler File Deletion
- System Log File Deletion
- Tampering of Bash Command-Line History
- Tampering of Shell Command-Line History
- Timestomping Detected via Touch
- Timestomping using Touch Command
- Unsigned or Untrusted Process Execution and Immediate Self-Deletion
- User Session File Deletion
- WebServer Access Logs Deleted
- Windows Event Logs Cleared
Splunk 46 rules
- Cisco ASA - Logging Message Suppression
- Cisco ASA - User Account Deleted From Local Database
- Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal
- Clear Command History
- Clear Linux System Logs
- Clear Unallocated Sector Using Cipher App
- Clear Windows Event Logs (PowerShell)
- Clear Windows Event Logs (Windows Event Log)
- Create or delete windows shares using net exe
- ESXi Audit Tampering
- ESXi System Clock Manipulation
- ETW Trace Provider Modified - PowerShell (PowerShell)
- Fsutil Zeroing File
- Linux Account Manipulation Of SSH Config and Keys
- Linux Deletion Of Cron Jobs
- Linux Deletion Of Init Daemon Script
- Linux Deletion Of Services
- Linux Deletion of SSL Certificate
- Linux High Frequency Of File Deletion In Boot Folder
- Linux High Frequency Of File Deletion In Etc Folder
- Linux Indicator Removal Clear Cache
- Linux Indicator Removal Service File Deletion
- MacOS Log Removal
- Network Share Connection Removal (PowerShell)
- NirCmd Execution (PowerShell)
- NirCmd Execution (Sysmon)
- NirCmd Execution (Windows Event Log)
- O365 Email Hard Delete Excessive Volume
- O365 Email Password and Payroll Compromise Behavior
- O365 Email Receive and Hard Delete Takeover Behavior
- O365 Email Send and Hard Delete Exfiltration Behavior
- O365 Email Send and Hard Delete Suspicious Behavior
- O365 Email Send Attachments Excessive Volume
- Process Deleting Its Process File Path
- Recursive Delete of Directory In Batch CMD
- Sdelete Application Execution
- Timestamp Manipulation (PowerShell)
- Timestamp Manipulation (Windows Event Log)
- USN Journal Deletion
- Windows ConsoleHost History File Deletion
- Windows Default Rdp File Deletion
- Windows Indicator Removal Via Rmdir
- Windows Powershell History File Deletion
- Windows Rdp AutomaticDestinations Deletion
- Windows RDP Cache File Deletion
- Windows RDP Server Registry Deletion
Kusto 30 rules
- AWSCloudTrail - Changes made to AWS CloudTrail logs
- Bitglass - The SmartEdge endpoint agent was uninstalled
- CiscoISE - Attempt to delete local store logs
- CiscoISE - Log files deleted
- Clearing of forensic evidence from event logs using wevtutil
- Dataverse - Audit log data deletion
- McAfee ePO - Attempt uninstall McAfee agent
- McAfee ePO - Error sending alert
- McAfee ePO - File added to exceptions
- McAfee ePO - Logging error occurred
- McAfee ePO - Multiple threats on same host
- McAfee ePO - Scanning engine disabled
- McAfee ePO - Task error
- McAfee ePO - Threat was not blocked
- McAfee ePO - Unable to clean or delete infected file
- McAfee ePO - Update failed
- NRT Security Event log cleared
- OCI - Event rule deleted
- Potential Ransomware activity related to Cobalt Strike
- Powershell Empire Cmdlets Executed in Command Line
- Qakbot Campaign Self Deletion
- SAP BTP - Build Work Zone unauthorized access and role tampering
- SAP BTP - Cloud Integration tampering with security material
- Security Event log cleared
- Sentinel One - Agent uninstalled from multiple hosts
- Sentinel One - Blacklist hash deleted
- Sentinel One - Exclusion added
- Sentinel One - Rule deleted
- Sentinel One - Rule disabled
- Tailscale: Mass credential revocation in short window