Cross-source coverage
T1070 / ATT&CK
Indicator Removal
245 rules · 236 families across 12 sources.
9 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.
These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.
- Tactics
- Stealth
- Platforms
- Containers · ESXi · Linux · macOS · Network Devices · Office Suite · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLlinux:climacos:unifiedlogfs:fsusagemacos:osquerydocker:daemonebpf:syscallsesxi:hostdm365:exchangem365:unified
How MITRE says to detect it DET0184
Behavioral Detection of Indicator Removal Across Platforms
Windows Analytic 0520
Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation.
WinEventLog:SysmonEventCode=23WinEventLog:SecurityEventCode=1102WinEventLog:SysmonEventCode=13, 14
Linux Analytic 0521
Detects deletion or overwriting of bash history, syslog, audit logs, and.ssh metadata following privilege elevation or suspicious process spawning.
auditd:SYSCALLunlink, rename, openlinux:clicleared or truncated .bash_history
macOS Analytic 0522
Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution.
macos:unifiedloglog stream cleared or truncatedfs:fsusageunlink, fs_deletemacos:osqueryFile modifications in ~/Library/Preferences/
Containers Analytic 0523
Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise.
docker:daemoncontainer file operationsebpf:syscallsUnexpected container volume unmount + file deletion
ESXi Analytic 0524
Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history.
esxi:hostdrm, clearlogs, logrotate
Office Suite Analytic 0525
Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.
m365:exchangeRemove-InboxRule, Clear-Mailboxm365:unifiedPurgeAuditLogs, Remove-MailboxAuditLog
Sub-techniques with coverage
Counted in the 245 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
55 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Clear Logs | High | Sigma |
| Clearing Windows Console History | High | Sigma |
| Disable of ETW Trace - Powershell | High | Sigma |
| Disable Powershell Command History | High | Sigma |
| ETW Trace Evasion Activity | High | Sigma |
| Exchange PowerShell Cmdlet History Deleted | High | Sigma |
| Fsutil Suspicious Invocation | High | Sigma |
| Linux Command History Tampering | High | Sigma |
| Prefetch File Deleted | High | Sigma |
| Remove Exported Mailbox from Exchange Webserver | High | Sigma |
+ 45 more from SigmaHQ/sigma → showing the 10 highest-severity
socfortress/Wazuh-Rules
44 rules · 42 families+ 34 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
35 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - Logging Message Suppression | Undefined | SPL |
| Cisco ASA - User Account Deleted From Local Database | Undefined | SPL |
| Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal | Undefined | SPL |
| Clear Unallocated Sector Using Cipher App | Undefined | SPL |
| Create or delete windows shares using net exe | Undefined | SPL |
| ESXi Audit Tampering | Undefined | SPL |
| ESXi System Clock Manipulation | Undefined | SPL |
| Fsutil Zeroing File | Undefined | SPL |
| Linux Account Manipulation Of SSH Config and Keys | Undefined | SPL |
| Linux Deletion Of Cron Jobs | Undefined | SPL |
+ 25 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
32 rules| Detection | Severity | Format |
|---|---|---|
| Attempt to Clear Kernel Ring Buffer | High | Elastic TOML |
| File Creation, Execution and Self-Deletion in Suspicious Directory | High | Elastic TOML |
| Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers | High | Elastic TOML |
| Potential REMCOS Trojan Execution | High | Elastic TOML |
| Shell Command-Line History Deletion Detected via Defend for Containers | High | Elastic TOML |
| Shell History Clearing via Environment Variables | High | Elastic TOML |
| Attempt to Clear Logs via Journalctl | Medium | Elastic TOML |
| Azure AKS Kubernetes Events Deleted | Medium | Elastic TOML |
| Clearing Windows Console History | Medium | Elastic TOML |
| ESXI Timestomping using Touch Command | Medium | Elastic TOML |
+ 22 more from elastic/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
29 rules| Detection | Severity | Format |
|---|---|---|
| Netscaler: UI/API dangerous command | High | Wazuh XML |
| An item has been deleted from quarantine | Medium | Wazuh XML |
| Docker: Container deleted · docker.status = delete | Medium | Wazuh XML |
| Docker: Volume destroyed in · docker.Action = destroy | Medium | Wazuh XML |
| File deleted. | Medium | Wazuh XML |
| File deletion by . Command · win.eventdata.originalFileName = (?i)sdelete\.exe | Medium | Wazuh XML |
| IPsec dropped an inbound clear text packet that should have been secured | Medium | Wazuh XML |
| IPsec dropped an inbound packet that failed a replay check | Medium | Wazuh XML |
| Microsoft Event log cleared. | Medium | Wazuh XML |
| Powershell executed a command that modifies file timestamp, possible timestomp attempt | Medium | Wazuh XML |
+ 19 more from Wazuh Core Ruleset → showing the 10 highest-severity
elastic/protections-artifacts
20 rules · 19 families| Detection | Severity | Format |
|---|---|---|
| Attempt to Clear Kernel Ring Buffer via Dmesg | Undefined | Elastic TOML |
| Attempt to Clear Logs via Journalctl | Undefined | Elastic TOML |
| Clearing of Shell History via Environment Variables | Undefined | Elastic TOML |
| Deletion of Shell History File | Undefined | Elastic TOML |
| Loadable Kernel Module Load Followed by Log Clearing | Undefined | Elastic TOML |
| Multiple System Log Files Deletion | Undefined | Elastic TOML |
| Node Script Execution and Immediate Deletion 2 variants | Undefined | Elastic TOML |
| Node Script Execution and Immediate Deletion 2 variants | Undefined | Elastic TOML |
| Potential Image Load with a Spoofed Creation Time | Undefined | Elastic TOML |
| Potential Self Deletion of a Running Executable | Undefined | Elastic TOML |
+ 10 more from elastic/protections-artifacts → showing the 10 highest-severity
panther-labs/panther-analysis
10 rules| Detection | Severity | Format |
|---|---|---|
| AWS RDS Snapshot Deleted | High | Panther Python |
| Crowdstrike Ephemeral User Account | High | Panther Python |
| Crowdstrike Systemlog Tampering | High | Panther Python |
| Crowdstrike User Deleted | High | Panther Python |
| Slack DLP Modified | High | Panther Python |
| Crowdstrike API Key Deleted | Medium | Panther Python |
| Slack App Removed | Medium | Panther Python |
| Wiz User Created Or Deleted | Low | Panther Python |
| Azure Automation Runbook Deleted | Informational | Panther Python |
| Databricks Access Token Revoked | Informational | Panther Python |
chainguard-dev/osquery-defense-kit
9 rules · 8 families| Detection | Severity | Format |
|---|---|---|
| Alert on programs running that are unusually old | Undefined | osquery SQL |
| A program where the parent PID is not on disk 2 variants | Undefined | osquery SQL |
| A program where the parent PID is not on disk 2 variants | Undefined | osquery SQL |
| Files where the timestamp falls along 12-hour boundaries - probably caused by 'touch <date>0000' | Undefined | osquery SQL |
| Processes that do not exist on disk | Undefined | osquery SQL |
| Processes that do not exist on disk, running in osquery's namespace | Undefined | osquery SQL |
| Programs which appear to have been touched on macOS | Undefined | osquery SQL |
| Programs which claim to be from the future, based on (btime,ctime,mtime) | Undefined | osquery SQL |
| Programs which were spawned by an executable containing a matching ctime & mtime, which | Undefined | osquery SQL |
Bert-JanP/Hunting-Queries-Detection-Rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Custom Detection Deletion | Undefined | KQL |
| Custom Detection Disabled | Undefined | KQL |
| Custom Detection Report for Microsoft Defender | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Security Log Cleared | Undefined | KQL |
| Wevutil Clear Windows Event Logs | Undefined | KQL |
Azure/Azure-Sentinel
2 rules| Detection | Severity | Format |
|---|---|---|
| Crash dump disabled on host (ASIM Version) | Undefined | KQL |
| RedMenshen-BPFDoor-backdoor | Undefined | KQL |
falcosecurity/rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Clear Log Activities | Medium | Falco YAML |
| Delete or rename shell history | Medium | Falco YAML |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| windows_event_log_cleared | Medium | YARA-L |