What MITRE ATT&CK T1070: Indicator Removal (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1070 covers adversary deletion or modification of artifacts generated by intrusion activity to evade detection and impede investigation. Sub-techniques include Clear Windows Event Logs (T1070.001), Clear Linux/macOS Logs (T1070.002), Clear Command History (T1070.003), File Deletion (T1070.004), Timestomp (T1070.006), Clear Network Connection History (T1070.007), Clear Mailbox Data (T1070.008), and Clear Persistence (T1070.009). Compliance obligations include immutable audit logging (NIST 800-53 AU-9, ISO A.8.15), centralised log forwarding required by PCI DSS Req 10.5, and tamper-evident storage under SOX 404 ITGC.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1070/
SHA-256 integrity: 83fc9bda3e0f019132f3120ea37cc17d48763f57cb751b8750f805e24458a1b0
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1070: Indicator Removal (https://attack.mitre.org/techniques/T1070/) with 9 sub-techniques
- NIST SP 800-53 Rev 5: AU-9 (Protection of Audit Information), AU-11 (Audit Record Retention)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access