Compliance Node Overview
MITRE ATT&CK T1070.007 (Clear Network Connection History and Configurations) is an Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as various artifacts that highlight connection history may be created on a system and/or in application logs from behaviors that require network connections, such as Remote Services or External Remote Services. Defenders may use these artifacts to monitor or otherwise analyze network connections created by adversaries. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1029 Remote Data Storage, M1024 Restrict Registry Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1070/007/
SHA-256 integrity: 125b893cf66e3e6b8285abaa43afdba84fb8e7032fbcd06898b6bdd55487b3a5
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1070.007: Clear Network Connection History and Configurations (https://attack.mitre.org/techniques/T1070/007/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access