T1070.009 Clear Persistence

Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence.(Citation: Cylance Dust Storm) Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account).(Citation: Talos - Cisco Attack 2022)

In some instances, artifacts of persistence may also be removed once an adversary’s persistence is executed in order to prevent errors with the new instance of the malware.(Citation: NCC Group Team9 June 2020)

View in MITRE ATT&CK®

NIST 800-53 Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
AC-02 Account Management mitigates T1070.009 Clear Persistence
CA-07 Continuous Monitoring mitigates T1070.009 Clear Persistence
CM-06 Configuration Settings mitigates T1070.009 Clear Persistence
SI-03 Malicious Code Protection mitigates T1070.009 Clear Persistence
SI-07 Software, Firmware, and Information Integrity mitigates T1070.009 Clear Persistence
CM-02 Baseline Configuration mitigates T1070.009 Clear Persistence
SI-04 System Monitoring mitigates T1070.009 Clear Persistence
AC-03 Access Enforcement mitigates T1070.009 Clear Persistence
AC-05 Separation of Duties mitigates T1070.009 Clear Persistence
AC-06 Least Privilege mitigates T1070.009 Clear Persistence

Azure Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
file_integrity_monitoring Microsoft Defender for Cloud: File Integrity Monitoring technique_scores T1070.009 Clear Persistence
Comments
This control can detect changes to files associated with this technique.
References
alerts_for_windows_machines Alerts for Windows Machines technique_scores T1070.009 Clear Persistence

GCP Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
google_secops Google Security Operations technique_scores T1070.009 Clear Persistence
Comments
Google Security Operations is able to trigger an alert when indicators are cleared from the infrastructure. This technique was scored as minimal based on low or uncertain detection coverage factor.
References

AWS Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
amazon_inspector Amazon Inspector technique_scores T1070.009 Clear Persistence
Comments
The Amazon Inspector Best Practices assessment package can assess security control "Configure permissions for system directories" that prevents privilege escalation by local users and ensures only the root account can modify/execute system configuration information and binaries. Amazon Inspector does not directly protect against system modifications rather it just checks to see if security controls are in place which can inform decisions around hardening the system. Due to this and the fact the security control is only supported for Linux platforms, the score is Minimal.
References