What MITRE ATT&CK T1070.004: File Deletion (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1070.004 (File Deletion) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1070/004/
SHA-256 integrity: 9104accece999b6d45b5d45002cfc3a0881e1a7c061bd6cfa40512a71e90d0bd
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1070.004: File Deletion (https://attack.mitre.org/techniques/T1070/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1070-004-file-deletion.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1070-004-file-deletion.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1070-004-file-deletion
- Back to registry: Browse all 10,085 compliance nodes