ESA SPACE-SHIELD
T1070

Indicator Removal on Host

Description

Adversaries may delete or modify artifacts generated on a host system to remove evidence of their presence or hinder defenses. Various artifacts may be created by an adversary or something that can be attributed to an adversary's actions. (Citation: MITRE ATT&CK)

Mapped SPARTA techniques

4 techniques

  • DE-0003.08Received CommandsST0006
    addresses
    high

    T1070 'Indicator Removal on Host' is the direct cross-framework counterpart of DE-0003.08 — both describe deleting/modifying artifacts (received-command histories, logs, file records) to remove evidence of attacker activity.

  • DE-0007Evasion via RootkitST0006
    addresses
    high

    T1070 'Indicator Removal on Host' is the direct cross-framework counterpart of DE-0007 — both describe rootkits removing evidence of attacker presence by manipulating host artifacts.

  • DE-0010Overflow Audit LogST0006
    addresses
    high

    T1070 'Indicator Removal on Host' covers deleting/modifying artifacts to remove evidence — direct match to DE-0010's exhaustion of audit-log buffers so incriminating events are overwritten before downlink.

  • EX-0010.03RootkitST0004
    addresses
    moderate

    T1070 'Indicator Removal on Host' parent covers deleting/modifying artifacts to hide presence — addresses rootkit's interposition on telemetry/event logging and concealment of malicious activity in EX-0010.03.

Cite as SafeMode Space, space-shield T1070.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.