{
  "node_id": "mitre-attack-t1070-indicator-removal",
  "title": "MITRE ATT&CK T1070: Indicator Removal (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-11",
  "bluf": "MITRE ATT&CK T1070 covers adversary deletion or modification of artifacts generated by intrusion activity to evade detection and impede investigation. Sub-techniques include Clear Windows Event Logs (T1070.001), Clear Linux/macOS Logs (T1070.002), Clear Command History (T1070.003), File Deletion (T1070.004), Timestomp (T1070.006), Clear Network Connection History (T1070.007), Clear Mailbox Data (T1070.008), and Clear Persistence (T1070.009). Compliance obligations include immutable audit logging (NIST 800-53 AU-9, ISO A.8.15), centralised log forwarding required by PCI DSS Req 10.5, and tamper-evident storage under SOX 404 ITGC.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "mitre-t1562",
    "pci-dss-v4-req-10-12-monitoring-policy"
  ],
  "primary_citations_count": 7
}