1200KM / detection
T1070.004 File Deletion — Detection Rules
Detection workspace for T1070.004 File Deletion: 13 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- File Deletion · stable · informational · {"product":"linux","category":"process_creation"}
- Cisco File Deletion · test · medium · {"product":"cisco","service":"aaa"}
- Backup Catalog Deleted · test · medium · {"product":"windows","service":"application"}
- Potential Secure Deletion with SDelete · test · medium · {"product":"windows","service":"security"}
- Prefetch File Deleted · test · high · {"product":"windows","category":"file_delete"}
- TeamViewer Log File Deleted · test · low · {"product":"windows","category":"file_delete"}
- File Deleted Via Sysinternals SDelete · test · medium · {"product":"windows","category":"file_delete"}
- ADS Zone.Identifier Deleted By Uncommon Application · test · medium · {"product":"windows","category":"file_delete"}
- File Deletion Via Del · test · low · {"category":"process_creation","product":"windows"}
- Greedy File Deletion Using Del · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Ping/Copy Command Combination · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Ping/Del Command Combination · test · high · {"category":"process_creation","product":"windows"}
- Directory Removal Via Rmdir · test · low · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1070.004 File Deletion
MATCH(deletion_of_executable_script_or_log_file) AND actor_or_path NOT_IN approved_deletion_activity -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0140 Behavioral Detection of Malicious File Deletion
AN0392 Analytic 0392
Detects adversary behavior deleting artifacts (e.g., dropped payloads, evidence files) using native or external utilities (e.g., del, erase, SDelete). Detects deletion events correlated with unusual process lineage or timing post-execution.
AN0393 Analytic 0393
Detects deletion of suspicious files (e.g., payloads, temp exes, scripts) via `rm`, `unlink`, or secure deletion tools like `shred`, especially when performed by unexpected users or shortly after execution.
AN0394 Analytic 0394
Detects removal of adversary artifacts via `rm`, `unlink`, or secure tools, with focus on shell sessions, temp files, and modified LaunchAgents or system directories.
AN0395 Analytic 0395
Detects manual or scripted removal of logs, artifacts, or malware droppings via `rm` or PowerCLI in ESXi shell. Focus on deletions from /tmp/, /var/core/, or /scratch.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- APT29 · G0016
- APT3 · G0022
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- Group5 · G0043
- menuPass · G0045
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- FIN5 · G0053
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- The White Company · G0089
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Rocke · G0106
- Chimera · G0114
- Evilnum · G0120
- Mustang Panda · G0129
- TeamTNT · G0139
- Aquatic Panda · G0143
- Ember Bear · G1003
- Metador · G1013
- Volt Typhoon · G1017
- APT5 · G1023
- INC Ransom · G1032
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.