Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1070 Indicator Removal

Stealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1070 (Indicator Removal) appears in 432 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
432191 critical, 209 high, 27 medium, 2 low
First seen
2021-11-25
Last seen
2026-09-27
Threat actors
133In the threats using it
Detection rules
150Blue tier and above

Data as of:

Activity timeline

T1070 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 171 reports, and 431 of the 432 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1070 Indicator Removal is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 432 of 2623 tracked threats (16.5%) to it; by severity that is 191 critical, 209 high, 27 medium, 2 low.

Threats that use T1070 most often also use T1059 Command and Scripting Interpreter (329 threats), T1071 Application Layer Protocol (291 threats), T1082 System Information Discovery (269 threats), T1005 Data from Local System (259 threats), T1027 Obfuscated Files or Information (257 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

133 tracked threat actors appear in the threats that use T1070; the most frequent are TeamPCP (16), APT38 (13), Sapphire Sleet (12), Stardust Chollima (12), Contagious Interview (8).

Mitigations

MITRE ATT&CK lists 3 mitigations for T1070.

Data sources

Telemetry that can reveal T1070, per MITRE ATT&CK.

  • Application Log — Application Log Content
  • Command — Command Execution
  • File — File Deletion, File Metadata, File Modification
  • Firewall — Firewall Rule Modification
  • Network Traffic — Network Traffic Content
  • Process — OS API Execution, Process Creation
  • Scheduled Job — Scheduled Job Modification
  • User Account — User Account Authentication, User Account Deletion
  • Windows Registry — Windows Registry Key Deletion, Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 432 tracked threats that use T1070.

Detection coverage

Threadlinqs maintains 150 detection rules mapped to T1070 (SPL 39, KQL 48, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.

150 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1070.001 Clear Windows Event Logs — 4 tracked threats
  • T1070.002 Clear Linux or Mac System Logs — 6 tracked threats
  • T1070.003 Clear Command History — 21 tracked threats
  • T1070.004 File Deletion — 207 tracked threats
  • T1070.005 Network Share Connection Removal — 1 tracked threat
  • T1070.006 Timestomp — 37 tracked threats
  • T1070.007 Clear Network Connection History and Configurations — 2 tracked threats
  • T1070.008 Clear Mailbox Data — 4 tracked threats
  • T1070.009 Clear Persistence — 6 tracked threats
  • T1070.010 Relocate Malware — 0 tracked threats