T1070.004File Deletion
T1070.004 — File Deletion is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 23 detection use cases covering it and 12 threat-intel articles citing it.
Defense Evasion
23Use cases
12Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1070 · Indicator Removal
Use cases covering this technique (23)
Clear Unallocated Sector Using Cipher App Linux Account Manipulation Of SSH Config and Keys Linux Deletion Of Cron Jobs Linux Deletion Of Init Daemon Script Linux Deletion Of Services Linux Deletion of SSL Certificate Linux High Frequency Of File Deletion In Boot Folder Linux High Frequency Of File Deletion In Etc Folder Linux Indicator Removal Service File Deletion Recursive Delete of Directory In Batch CMD Sdelete Application Execution Windows Default Rdp File Deletion Windows Rdp AutomaticDestinations Deletion Windows RDP Cache File Deletion Windows RDP Server Registry Deletion [LLM] Anti-forensic deletion/tampering of macOS Tahoe 26 App.MenuItem Biome stream [LLM] MIPS shell-script dropper on Linux edge device — JDY architecture-aware payload fetch [LLM] AWS CloudTrail S3 destination bucket emptied or deleted [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) [LLM] PowerShell-parented taskkill of winrar.exe (Cloud Atlas LNK anti-forensic cleanup) [LLM] Trinny marker file creation (.trinny-security-update) [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics)Articles citing this technique (12)
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219