File Eviction
Description
File eviction techniques delete files from system storage.
Mapped SPARTA techniques
16 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0003.12 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because DE-0003.12 spans both a ground and a space face while the control reaches only one of them.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records DE-0009.05 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.01 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.02 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.03 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.04 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.05 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.06 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.07 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.08 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.09 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.10 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.11 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.12 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that File Eviction counters T1565.001 Stored Data Manipulation; SafeMode's curated mapping records EX-0012.13 as addressing that same adversary behaviour in the space domain. Deleting an unauthorised file from storage applies to on-board file stores and table areas as well as to ground hosts. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because EX-0012.13 spans both a ground and a space face while the control reaches only one of them.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 96 in MITRE ATT&CK Enterprise
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1005Data from Local System
- T1014Rootkit
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.004Compile After Delivery
- T1033System Owner/User Discovery
- T1036.001Invalid Code Signature
- T1036.003Rename Legitimate Utilities
- T1036.005Match Legitimate Resource Name or Location
- T1036.006Space after Filename
- T1037.001Logon Script (Windows)
- T1037.002Login Hook
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1041Exfiltration Over C2 Channel
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1055.001Dynamic-link Library Injection
- T1055.002Portable Executable Injection
- T1055.003Thread Execution Hijacking
- T1055.009Proc Memory
- T1055.014VDSO Hijacking
- T1059Command and Scripting Interpreter
- T1070.002Clear Linux or Mac System Logs
- T1070.004File Deletion
- T1071Application Layer Protocol
- T1071.001Web Protocols
- T1072Software Deployment Tools
- T1074.001Local Data Staging
- T1083File and Directory Discovery
- T1114.001Local Email Collection
- T1119Automated Collection
- T1127.001MSBuild
- T1137.001Office Template Macros
- T1137.003Outlook Forms
- T1140Deobfuscate/Decode Files or Information
- T1187Forced Authentication
- T1204.002Malicious File
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1486Data Encrypted for Impact
- T1505.003Web Shell
- T1534Internal Spearphishing
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.004Launch Daemon
- T1546.002Screensaver
- T1546.004Unix Shell Configuration Modification
- T1546.005Trap
- T1546.006LC_LOAD_DYLIB Addition
- T1546.008Accessibility Features
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1546.013PowerShell Profile
- T1546.014Emond
- T1546.015Component Object Model Hijacking
- T1547.001Registry Run Keys / Startup Folder
- T1547.006Kernel Modules and Extensions
- T1547.007Re-opened Applications
- T1547.008LSASS Driver
- T1547.009Shortcut Modification
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1552.001Credentials In Files
- T1552.003Shell History
- T1555Credentials from Password Stores
- T1555.003Credentials from Web Browsers
- T1556.002Password Filter DLL
- T1556.003Pluggable Authentication Modules
- T1560Archive Collected Data
- T1560.001Archive via Utility
- T1560.002Archive via Library
- T1560.003Archive via Custom Method
- T1562.003Impair Command History Logging
- T1564.002Hidden Users
- T1564.003Hidden Window
- T1564.006Run Virtual Instance
- T1564.007VBA Stomping
- T1565.001Stored Data Manipulation
- T1565.003Runtime Data Manipulation
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1566.003Spearphishing via Service
- T1573.002Asymmetric Cryptography
- T1574.001DLL
- T1574.004Dylib Hijacking
- T1574.006Dynamic Linker Hijacking
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
- T1574.012COR_PROFILER
- T1649Steal or Forge Authentication Certificates
Cite as SafeMode Space, d3fend D3-FEV.