Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1070.004

T1070.004File Deletion

T1070.004 — File Deletion is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 29 detection use cases covering it and 19 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
29Use cases
19Articles
0Sub-techniques
1Tactic

Use cases covering this technique (29)

Clear Unallocated Sector Using Cipher App ESCU actions · alerting P Linux Account Manipulation Of SSH Config and Keys ESCU actions · hunting P Linux Deletion Of Cron Jobs ESCU actions · hunting P Linux Deletion Of Init Daemon Script ESCU actions · alerting P Linux Deletion Of Services ESCU actions · alerting P Linux Deletion of SSL Certificate ESCU actions · hunting P Linux High Frequency Of File Deletion In Boot Folder ESCU actions · alerting P Linux High Frequency Of File Deletion In Etc Folder ESCU actions · hunting P Linux Indicator Removal Service File Deletion ESCU actions · hunting P Recursive Delete of Directory In Batch CMD ESCU actions · alerting P Sdelete Application Execution ESCU actions · alerting P Windows Default Rdp File Deletion ESCU actions · hunting P Windows Rdp AutomaticDestinations Deletion ESCU actions · hunting P Windows RDP Cache File Deletion ESCU actions · hunting P Windows RDP Server Registry Deletion ESCU actions · hunting P [LLM] goshs process deletes or renames served files while launched with --no-delete (impact confirmation) Bespoke actions · alerting DSΣPDDCS [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) Bespoke install · alerting DSΣPDDCS [LLM] Vitest Browser Mode node.exe writes/deletes PNG or trace archive outside project into system paths Bespoke actions · alerting DSΣPDDCS [LLM] DIRAC service process deletes or truncates its own logs (anti-forensics post-RCE) Bespoke actions · hunting DSΣPDDCS [LLM] Sha1-Hulud destructive wiper fallback (cipher /W, recursive del, shred over home dir) Bespoke actions · alerting DSΣPDDCS [LLM] Package-manager dropper self-deletion inside node_modules (evidence erasure) Bespoke actions · hunting DSΣPDDCS [LLM] easy-day-js malicious setup.cjs written/deleted under node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory Bespoke install · hunting DSΣPDDCS [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] Trinny marker file creation (.trinny-security-update) Bespoke install · alerting DSΣPDDCS [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules Bespoke install · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] SuiteCRM upload/files .htaccess deleted by web-server process (PHAR gadget) Bespoke actions · alerting DSΣPCS

Articles citing this technique (19)