Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1070.004

T1070.004File Deletion

T1070.004 — File Deletion is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 29 detection use cases covering it and 17 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
29Use cases
17Articles
0Sub-techniques
1Tactic

Use cases covering this technique (29)

Clear Unallocated Sector Using Cipher App ESCU actions · alerting P Linux Account Manipulation Of SSH Config and Keys ESCU actions · hunting P Linux Deletion Of Cron Jobs ESCU actions · hunting P Linux Deletion Of Init Daemon Script ESCU actions · alerting P Linux Deletion Of Services ESCU actions · alerting P Linux Deletion of SSL Certificate ESCU actions · hunting P Linux High Frequency Of File Deletion In Boot Folder ESCU actions · alerting P Linux High Frequency Of File Deletion In Etc Folder ESCU actions · hunting P Linux Indicator Removal Service File Deletion ESCU actions · hunting P Recursive Delete of Directory In Batch CMD ESCU actions · alerting P Sdelete Application Execution ESCU actions · alerting P Windows Default Rdp File Deletion ESCU actions · hunting P Windows Rdp AutomaticDestinations Deletion ESCU actions · hunting P Windows RDP Cache File Deletion ESCU actions · hunting P Windows RDP Server Registry Deletion ESCU actions · hunting P [LLM] Client-side WebDAV MOVE with Overwrite:T header (goshs --no-delete bypass exploitation) Bespoke actions · alerting DSΣPDDCS [LLM] WebDAV DELETE blocked (403) then MOVE succeeds (2xx) — goshs --no-delete bypass signature Bespoke actions · alerting SP [LLM] Vitest Browser Mode node.exe writes/deletes PNG or trace archive outside project into system paths Bespoke actions · alerting DSΣPDDCS [LLM] DIRAC service process deletes or truncates its own logs (anti-forensics post-RCE) Bespoke actions · hunting DSΣPDDCS [LLM] Sha1-Hulud destructive wiper fallback (cipher /W, recursive del, shred over home dir) Bespoke actions · alerting DSΣPDDCS [LLM] Package-manager dropper self-deletion inside node_modules (evidence erasure) Bespoke actions · hunting DSΣPDDCS [LLM] easy-day-js malicious setup.cjs written/deleted under node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory Bespoke install · hunting DSΣPDDCS [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] Trinny marker file creation (.trinny-security-update) Bespoke install · alerting DSΣPDDCS [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules Bespoke install · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] SuiteCRM upload/files .htaccess deleted by web-server process (PHAR gadget) Bespoke actions · alerting DSΣPCS

Articles citing this technique (17)