Compliance Node Overview
MITRE ATT&CK T0872 (Indicator Removal on Host) is an ATT&CK for ICS Evasion technique. Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks. In cases where an adversary may feel detection is imminent, they may try to overwrite, delete, or cover up changes they have made to the device. Affected asset classes: None. MITRE-documented mitigations include M0922 Restrict File and Directory Permissions. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0872/
SHA-256 integrity: 485800d566cf5bc1827497589ded60e71571216a1283b44f5fd343b490e08dff
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0872: Indicator Removal on Host (https://attack.mitre.org/techniques/T0872/)
- MITRE ATT&CK ICS Tactic TA0103: Evasion (https://attack.mitre.org/tactics/TA0103/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.