Indicator Removal on Host
Description
Adversaries may delete or modify artifacts generated on a host system to remove evidence of their presence or hinder defenses. Various artifacts may be created by an adversary or something that can be attributed to an adversary's actions. (Citation: MITRE ATT&CK)
Mapped SPARTA techniques
4 techniques
T1070 'Indicator Removal on Host' is the direct cross-framework counterpart of DE-0003.08 — both describe deleting/modifying artifacts (received-command histories, logs, file records) to remove evidence of attacker activity.
T1070 'Indicator Removal on Host' is the direct cross-framework counterpart of DE-0007 — both describe rootkits removing evidence of attacker presence by manipulating host artifacts.
T1070 'Indicator Removal on Host' covers deleting/modifying artifacts to remove evidence — direct match to DE-0010's exhaustion of audit-log buffers so incriminating events are overwritten before downlink.
T1070 'Indicator Removal on Host' parent covers deleting/modifying artifacts to hide presence — addresses rootkit's interposition on telemetry/event logging and concealment of malicious activity in EX-0010.03.
Cite as SafeMode Space, space-shield T1070.