EXPLORE
← Back to Explore
T1027.005

Indicator Removal from Tools

Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarant...

LinuxmacOSWindows
6
Detections
2
Sources
7
Threat Actors

BY SOURCE

4sigma2splunk_escu

PROCEDURES (4)

Obfuscat2 detections

Auto-extracted: 2 detections for obfuscat

Evasion2 detections

Auto-extracted: 2 detections for evasion

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

Script Block1 detections

Auto-extracted: 1 detections for script block

DETECTIONS (6)