Cross-source coverage

T1066 / ATT&CK

Indicator Removal from Tools

ATT&CK has retired this technique. Rules still tag it; the current id is T1027.005 Obfuscated Files or Information: Indicator Removal from Tools.

0 rules across 0 sources.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

If a malicious tool is detected and quarantined or otherwise curtailed, an adversary may be able to determine why the malicious tool was detected (the indicator), modify the tool by removing the indicator, and use the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems.

A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may use Software Packing or otherwise modify the file so it has a different signature, and then re-use the malware.

Tactics
Stealth
Platforms
Linux · macOS · Windows
Telemetry

No live rules cover this technique. 1 deprecated rule is hidden.

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.