{
  "node_id": "mitre-attack-t1027-005-indicator-removal-from-tools",
  "title": "MITRE ATT&CK T1027.005: Indicator Removal from Tools (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1027.005 (Indicator Removal from Tools) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1027-obfuscated-files-information"
  ],
  "primary_citations_count": 6
}