Cross-source coverage

T1070 / ATT&CK

Indicator Removal

254 rules · 245 families across 12 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.

Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system activity. Location, format, and type of artifact (such as command or login history) are often platform-specific, allowing adversaries to tailor modifications that minimize suspicion.

These actions may not prevent detection entirely but can delay recognition of malicious activity or reduce the fidelity of alerts by making events appear benign or consistent with routine operations. Additionally, selectively removed or modified artifacts may still be recoverable through deeper forensic analysis, though their absence or alteration can complicate timeline reconstruction and attribution.

Tactics
Stealth
Platforms
Containers · ESXi · Linux · macOS · Network Devices · Office Suite · Windows
Telemetry
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLlinux:climacos:unifiedlogfs:fsusagemacos:osquerydocker:daemonebpf:syscallsesxi:hostdm365:exchangem365:unified

How MITRE says to detect it DET0184

Behavioral Detection of Indicator Removal Across Platforms

Windows Analytic 0520

Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation.

  • WinEventLog:Sysmon EventCode=23
  • WinEventLog:Security EventCode=1102
  • WinEventLog:Sysmon EventCode=13, 14

Linux Analytic 0521

Detects deletion or overwriting of bash history, syslog, audit logs, and.ssh metadata following privilege elevation or suspicious process spawning.

  • auditd:SYSCALL unlink, rename, open
  • linux:cli cleared or truncated .bash_history

macOS Analytic 0522

Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution.

  • macos:unifiedlog log stream cleared or truncated
  • fs:fsusage unlink, fs_delete
  • macos:osquery File modifications in ~/Library/Preferences/

Containers Analytic 0523

Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise.

  • docker:daemon container file operations
  • ebpf:syscalls Unexpected container volume unmount + file deletion

ESXi Analytic 0524

Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history.

  • esxi:hostd rm, clearlogs, logrotate

Office Suite Analytic 0525

Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.

  • m365:exchange Remove-InboxRule, Clear-Mailbox
  • m365:unified PurgeAuditLogs, Remove-MailboxAuditLog

Sub-techniques with coverage

Counted in the 254 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

55 rules
Detection Severity Format
Cisco Clear Logs High Sigma
Clearing Windows Console History High Sigma
Disable of ETW Trace - Powershell High Sigma
Disable Powershell Command History High Sigma
ETW Trace Evasion Activity High Sigma
Exchange PowerShell Cmdlet History Deleted High Sigma
Fsutil Suspicious Invocation High Sigma
Linux Command History Tampering High Sigma
Prefetch File Deleted High Sigma
Remove Exported Mailbox from Exchange Webserver High Sigma

+ 45 more from SigmaHQ/sigma → showing the 10 highest-severity

socfortress/Wazuh-Rules

44 rules · 42 families
Detection Severity Format
Command to read or clear data using /dev/null detected: cat /dev/null High Wazuh XML
Command to read or clear data using /dev/null detected: cat /dev/null command = cat /dev/null High Wazuh XML
Command to remove bash history detected: rm /root/.bash_history High Wazuh XML
Command to remove bash history detected: rm /root/.bash_history command = rm /root/.bash_history High Wazuh XML
Command to symlink /root/.bash_history to /dev/null detected: ln -sf High Wazuh XML
Command to symlink /root/.bash_history to /dev/null detected: ln -sf command = ln -sf /dev/null /root/.bash_history High Wazuh XML
Detect file time attribute change to hide new or changes to existing files. 2 variants High Wazuh XML
Detect file time attribute change to hide new or changes to existing files. 2 variants High Wazuh XML
Direct mailbox access or tampering attempt (T1070.008) command= sudo cp /var/spool/mail/testuser /var/spool/mail/mail/testuser.bak High Wazuh XML
Log shredding detected (T1070.002) High Wazuh XML

+ 34 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

35 rules
Detection Severity Format
Cisco ASA - Logging Message Suppression Undefined SPL
Cisco ASA - User Account Deleted From Local Database Undefined SPL
Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal Undefined SPL
Clear Unallocated Sector Using Cipher App Undefined SPL
Create or delete windows shares using net exe Undefined SPL
ESXi Audit Tampering Undefined SPL
ESXi System Clock Manipulation Undefined SPL
Fsutil Zeroing File Undefined SPL
Linux Account Manipulation Of SSH Config and Keys Undefined SPL
Linux Deletion Of Cron Jobs Undefined SPL

+ 25 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

33 rules
Detection Severity Format
Attempt to Clear Kernel Ring Buffer High Elastic TOML
File Creation, Execution and Self-Deletion in Suspicious Directory High Elastic TOML
Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers High Elastic TOML
Potential REMCOS Trojan Execution High Elastic TOML
Shell Command-Line History Deletion Detected via Defend for Containers High Elastic TOML
Shell History Clearing via Environment Variables High Elastic TOML
Attempt to Clear Logs via Journalctl Medium Elastic TOML
Azure AKS Kubernetes Events Deleted Medium Elastic TOML
Clearing Windows Console History Medium Elastic TOML
Deprecated - Process Termination followed by Deletion Medium Elastic TOML

+ 23 more from elastic/detection-rules → showing the 10 highest-severity

Wazuh Core Ruleset

29 rules
Detection Severity Format
Netscaler: UI/API dangerous command High Wazuh XML
An item has been deleted from quarantine Medium Wazuh XML
Docker: Container deleted · docker.status = delete Medium Wazuh XML
Docker: Volume destroyed in · docker.Action = destroy Medium Wazuh XML
File deleted. Medium Wazuh XML
File deletion by . Command · win.eventdata.originalFileName = (?i)sdelete\.exe Medium Wazuh XML
IPsec dropped an inbound clear text packet that should have been secured Medium Wazuh XML
IPsec dropped an inbound packet that failed a replay check Medium Wazuh XML
Microsoft Event log cleared. Medium Wazuh XML
Powershell executed a command that modifies file timestamp, possible timestomp attempt Medium Wazuh XML

+ 19 more from Wazuh Core Ruleset → showing the 10 highest-severity

elastic/protections-artifacts

20 rules · 19 families
Detection Severity Format
Attempt to Clear Kernel Ring Buffer via Dmesg Undefined Elastic TOML
Attempt to Clear Logs via Journalctl Undefined Elastic TOML
Clearing of Shell History via Environment Variables Undefined Elastic TOML
Deletion of Shell History File Undefined Elastic TOML
Loadable Kernel Module Load Followed by Log Clearing Undefined Elastic TOML
Multiple System Log Files Deletion Undefined Elastic TOML
Node Script Execution and Immediate Deletion 2 variants Undefined Elastic TOML
Node Script Execution and Immediate Deletion 2 variants Undefined Elastic TOML
Potential Image Load with a Spoofed Creation Time Undefined Elastic TOML
Potential Self Deletion of a Running Executable Undefined Elastic TOML

+ 10 more from elastic/protections-artifacts → showing the 10 highest-severity

panther-labs/panther-analysis

10 rules
Detection Severity Format
AWS RDS Snapshot Deleted High Panther Python
Crowdstrike Ephemeral User Account High Panther Python
Crowdstrike Systemlog Tampering High Panther Python
Crowdstrike User Deleted High Panther Python
Slack DLP Modified High Panther Python
Crowdstrike API Key Deleted Medium Panther Python
Slack App Removed Medium Panther Python
Wiz User Created Or Deleted Low Panther Python
Azure Automation Runbook Deleted Informational Panther Python
Databricks Access Token Revoked Informational Panther Python

chainguard-dev/osquery-defense-kit

9 rules · 8 families
Detection Severity Format
Alert on programs running that are unusually old Undefined osquery SQL
A program where the parent PID is not on disk 2 variants Undefined osquery SQL
A program where the parent PID is not on disk 2 variants Undefined osquery SQL
Files where the timestamp falls along 12-hour boundaries - probably caused by 'touch <date>0000' Undefined osquery SQL
Processes that do not exist on disk Undefined osquery SQL
Processes that do not exist on disk, running in osquery's namespace Undefined osquery SQL
Programs which appear to have been touched on macOS Undefined osquery SQL
Programs which claim to be from the future, based on (btime,ctime,mtime) Undefined osquery SQL
Programs which were spawned by an executable containing a matching ctime & mtime, which Undefined osquery SQL

chronicle/detection-rules

9 rules
Detection Severity Format
windows_event_log_cleared Medium YARA-L
backup_catalog_deleted Undefined YARA-L
emotet_through_word_document_sysmon_behavior Undefined YARA-L
eventlog_cleared Undefined YARA-L
file_deletion_via_cmd_via_cmdline Undefined YARA-L
klist_purge Undefined YARA-L
possible_ransomware_or_unauthorized_mbr_modifications Undefined YARA-L
security_eventlog_cleared Undefined YARA-L
wastedlocker_ransomware_hunting_defense_evasion Undefined YARA-L

Bert-JanP/Hunting-Queries-Detection-Rules

6 rules
Detection Severity Format
Custom Detection Deletion Undefined KQL
Custom Detection Disabled Undefined KQL
Custom Detection Report for Microsoft Defender Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Security Log Cleared Undefined KQL
Wevutil Clear Windows Event Logs Undefined KQL

Azure/Azure-Sentinel

2 rules
Detection Severity Format
Crash dump disabled on host (ASIM Version) Undefined KQL
RedMenshen-BPFDoor-backdoor Undefined KQL

falcosecurity/rules

2 rules
Detection Severity Format
Clear Log Activities Medium Falco YAML
Delete or rename shell history Medium Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.