TACTIC: DEFENSE EVASION
Indicator Removal (T1070): real cases
MITRE Definition ↗ Adversaries delete event logs and temporary files to hinder incident response and forensic attribution.
Key Facts
Technique ID
T1070
Defense Evasion
Mapped Cases
2
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1070.
- Tactical Phase: Defense Evasion.
- Substantiated in 2 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Joshua Schulte (CIA Vault 7 Leak)
sentenced 2017-08-24
Primary Source Evidence Excerpt: Indictment ¶ 18, Page 11
"Defendant deleted server log files and altered system configuration timestamps to conceal his exfiltration of the CIA development branch."
U.S. District Court for the Southern District of New York
View full case dossier →
U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)
fugitive 2020-01-28
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 11
"Defendants routinely deleted temporary files and log entries, routed communications through encrypted tunnels, and ran roughly 9,000 queries to mask their database reconnaissance."
U.S. District Court for the Northern District of Georgia
View full case dossier →