Indicator Removal on Host T1630

Mobile Tactic: Defense Evasion

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (6 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1eq 1THREAT
ThreatAction1eq 1DETECTED
ThreatSeverity1in 1CRITICAL, HIGH
ThreatStatus1in 1ACTIVE, OPEN
entries1is_not_null 1
result_type1eq 1maliciousness

Top indicator values (7 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
THREAT
1
ThreatActioneq
DETECTED
1
ThreatSeverityin
CRITICAL
1
ThreatSeverityin
HIGH
1
ThreatStatusin
ACTIVE
1
ThreatStatusin
OPEN
1
result_typeeq
maliciousness
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Application

Domain: Application

Kusto 2 rules