Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various actions, such as removing services, deleting executables, Modify Registry, Plist File Modification, or other methods of cleanup to prevent defenders from collecting evidence of their persistent presence.(Citation: Cylance Dust Storm) Adversaries may also delete accounts previously created to maintain persistence (i.e. Create Account).(Citation: Talos - Cisco Attack 2022)
In some instances, artifacts of persistence may also be removed once an adversary’s persistence is executed in order to prevent errors with the new instance of the malware.(Citation: NCC Group Team9 June 2020)
View in MITRE ATT&CK®Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
AC-02 | Account Management | mitigates | T1070.009 | Clear Persistence | |
CA-07 | Continuous Monitoring | mitigates | T1070.009 | Clear Persistence | |
CM-06 | Configuration Settings | mitigates | T1070.009 | Clear Persistence | |
SI-03 | Malicious Code Protection | mitigates | T1070.009 | Clear Persistence | |
SI-07 | Software, Firmware, and Information Integrity | mitigates | T1070.009 | Clear Persistence | |
CM-02 | Baseline Configuration | mitigates | T1070.009 | Clear Persistence | |
SI-04 | System Monitoring | mitigates | T1070.009 | Clear Persistence | |
AC-03 | Access Enforcement | mitigates | T1070.009 | Clear Persistence | |
AC-05 | Separation of Duties | mitigates | T1070.009 | Clear Persistence | |
AC-06 | Least Privilege | mitigates | T1070.009 | Clear Persistence |
Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
file_integrity_monitoring | Microsoft Defender for Cloud: File Integrity Monitoring | technique_scores | T1070.009 | Clear Persistence |
Comments
This control can detect changes to files associated with this technique.
References
|
alerts_for_windows_machines | Alerts for Windows Machines | technique_scores | T1070.009 | Clear Persistence |
Comments
This control can monitor for executed commands associated with this technique.
References
|
Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
google_secops | Google Security Operations | technique_scores | T1070.009 | Clear Persistence |
Comments
Google Security Operations is able to trigger an alert when indicators are cleared from the infrastructure. This technique was scored as minimal based on low or uncertain detection coverage factor.
References
|
Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
amazon_inspector | Amazon Inspector | technique_scores | T1070.009 | Clear Persistence |
Comments
The Amazon Inspector Best Practices assessment package can assess security control "Configure permissions for system directories" that prevents privilege escalation by local users and ensures only the root account can modify/execute system configuration information and binaries. Amazon Inspector does not directly protect against system modifications rather it just checks to see if security controls are in place which can inform decisions around hardening the system. Due to this and the fact the security control is only supported for Linux platforms, the score is Minimal.
References
|