1200KM / detection
T0872 Indicator Removal on Host — Detection Rules
Detection workspace for T0872 Indicator Removal on Host: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0750 Detection of Indicator Removal on Host
AN1882 Analytic 1882
Monitor executed commands and arguments that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. Monitor for API calls that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. Monitor for changes made to Windows Registry keys or values that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. For added context on adversary procedures and background see Indicator Removal and applicable sub-techniques. Monitor for contextual file data that may show signs of deletion or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. Monitor Windows registry keys that may be deleted or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. For added context on adversary procedures and background see Indicator Removal and applicable sub-techniques. Monitor for a file that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. Monitor for changes made to a file may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware. Monitor for newly executed processes that may delete or alter generated artifacts on a host system, including logs or captured files such as quarantined malware.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- OS API Execution · DC0021
- Process Creation · DC0032
- Windows Registry Key Deletion · DC0045
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.