1200KM / simulation
T1070.004 File Deletion — Attack Simulation
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host…
Technique description
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Overwrite and delete a file with shred
Procedure 039b4b10-2900-404b-b67f-4b6d49aa6499; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete Prefetch File
Procedure 36f96049-0ad7-4a5f-8418-460acaeb92fb; elevation required; cleanup not declared. Not executed or individually validated.
- Delete a single file - FreeBSD/Linux/macOS
Procedure 562d737f-2fc6-4b09-8c2a-7f8ff0828480; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Delete TeamViewer Log Files
Procedure 69f50a5f-967c-4327-a5bb-e1a9a9983785; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete a single file - Windows cmd
Procedure 861ea0b4-708a-4d17-848d-186c9c7f17e3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete a single file - Windows PowerShell
Procedure 9dee89bd-9a98-4c4f-9e2d-4256690b0e72; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete an entire folder - FreeBSD/Linux/macOS
Procedure a415f17e-ce8d-4ce2-a8b4-83b674e7017e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete an entire folder - Windows cmd
Procedure ded937c4-2add-42f7-9c2c-c742b7a98698; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete an entire folder - Windows PowerShell
Procedure edd779e4-a509-4cba-8dfa-a112543dbfb1; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Delete Filesystem - Linux
Procedure f3aa95fe-4f10-4485-ad26-abf22a764c52; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Clears Recycle bin via rd
Procedure f723d13d-48dc-4317-9990-cf43a9ac0bf2; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- APT29 · G0016
- APT3 · G0022
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- Patchwork · G0040
- Group5 · G0043
- menuPass · G0045
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- FIN5 · G0053
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- The White Company · G0089
- Silence · G0091
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Rocke · G0106
- Chimera · G0114
- Evilnum · G0120
- Mustang Panda · G0129
- TeamTNT · G0139
- Aquatic Panda · G0143
- Ember Bear · G1003
- Metador · G1013
- Volt Typhoon · G1017
- APT5 · G1023
- INC Ransom · G1032
- RedCurl · G1039
- Play · G1040
- BlackByte · G1043
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.