Indicator Removal
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior. Artifacts such as command histories, log entries, or file metadata may be altered in ways that align with expected user or system...
BY SOURCE
PROCEDURES (32)
Auto-extracted: 11 detections for general monitoring
Auto-extracted: 10 detections for process creation monitoring
Auto-extracted: 2 detections for file monitoring
Auto-extracted: 2 detections for event log
Auto-extracted: 2 detections for cloud
Auto-extracted: 2 detections for powershell
Auto-extracted: 2 detections for driver
Auto-extracted: 2 detections for cloud monitoring
Auto-extracted: 2 detections for kubernetes
Auto-extracted: 2 detections for authentication monitoring
Auto-extracted: 2 detections for evasion
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for container
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for container
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for registry
Auto-extracted: 1 detections for event log
Auto-extracted: 1 detections for cloud
Auto-extracted: 1 detections for evasion
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for event log
Auto-extracted: 1 detections for container
Auto-extracted: 1 detections for event log