Cross-source coverage

T1107 / ATT&CK

File Deletion

ATT&CK has retired this technique. Rules still tag it; the current id is T1070.004 Indicator Removal: File Deletion.

6 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples include native cmd functions such as DEL, secure deletion tools such as Windows Sysinternals SDelete, or other third-party file deletion tools.

Tactics
Stealth
Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

3 rules
Detection Severity Format
a_variant_of_data_stealer_trojan_activity Undefined YARA-L
backup_catalog_deleted Undefined YARA-L
secure_deletion_with_sdelete Undefined YARA-L

socfortress/Wazuh-Rules

3 rules
Detection Severity Format
Windows Security log was cleared. High Wazuh XML
Sysmon - Event 23: FileDelete (A file delete was detected) by · system.eventID = 23 Low Wazuh XML
Sysmon - Event 23: FileDelete (A file delete was detected) by · win.system.eventID = 23 Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.