{"id":"T1027.005","name":"Indicator Removal from Tools","url":"https://attack.mitre.org/techniques/T1027/005","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0189","stix_id":"x-mitre-detection-strategy--6ab338c4-9ed3-4f63-9462-b13cea5a68b0","name":"Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification","url":"https://attack.mitre.org/detectionstrategies/DET0189","analytics":[{"id":"AN0540","stix_id":"x-mitre-analytic--2c94147a-a556-4fa1-92f8-d3c4367f6f2e","name":"Analytic 0540","description":"Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).","url":"https://attack.mitre.org/detectionstrategies/DET0189#AN0540","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Application","channel":"EventCode=1000","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AVAlertMessage","description":"Vendor-specific signature string or detection message that can be correlated to threat intel context."},{"field":"TimeWindow","description":"The time between AV alert and similar file/process activity (e.g., 5–30 minutes)"},{"field":"FilenameSimilarityThreshold","description":"String or hash similarity thresholds between original and modified binary."}],"live":true,"detection_strategies":["DET0189"],"techniques":["T1027.005"]},{"id":"AN0541","stix_id":"x-mitre-analytic--66bab948-9baa-4f5c-b259-333eb2ac08ad","name":"Analytic 0541","description":"Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain.","url":"https://attack.mitre.org/detectionstrategies/DET0189#AN0541","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open, rename","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"file_events","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"},{"name":"EDR:detection","channel":"ThreatDetected, QuarantineLog","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"edr-detection"}],"mutable_elements":[{"field":"PathWatchlist","description":"Tunable list of directories often abused for dropped binaries (e.g., /tmp, ~/.cache, /opt/soft/)."},{"field":"ProcessAncestryDepth","description":"Limit how far up the tree to trace tool modification behavior for detection."}],"live":true,"detection_strategies":["DET0189"],"techniques":["T1027.005"]},{"id":"AN0542","stix_id":"x-mitre-analytic--3ef92295-ecbf-417a-b72a-f6cd189ca3a1","name":"Analytic 0542","description":"Detection of XProtect or AV quarantining a known tool, followed by modification (file size, hash, string) and subsequent re-execution by the same or related user.","url":"https://attack.mitre.org/detectionstrategies/DET0189#AN0542","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"quarantine or AV-related subsystem","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"BinaryChangeThreshold","description":"File hash delta or binary string diff score to tolerate renamed/mutated variants."},{"field":"UserContext","description":"User or group expected to use dev tools; reduce false positives from legitimate repacking."}],"live":true,"detection_strategies":["DET0189"],"techniques":["T1027.005"]}],"live":true,"version":"1.0","techniques":["T1027.005"]}],"sigma_rules":[{"id":"0c92f2e6-f08f-4b73-9216-ecb0ca634689","title":"PUA - Potential PE Metadata Tamper Using Rcedit","author":"Micah Babinski","status":"test","level":"medium","date":"2022-12-11","modified":"2023-03-05","description":"Detects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.","references":["https://security.stackexchange.com/questions/210843/is-it-possible-to-change-original-filename-of-an-exe","https://www.virustotal.com/gui/file/02e8e8c5d430d8b768980f517b62d7792d690982b9ba0f7e04163cbc1a6e7915","https://github.com/electron/rcedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.003","attack.t1036","attack.t1027.005","attack.t1027"],"path":"rules/windows/process_creation/proc_creation_win_pua_rcedit_execution.yml","techniques":["T1036.003","T1036","T1027.005","T1027"],"cves":[]},{"id":"39a80702-d7ca-4a83-b776-525b1f86a36d","title":"Potential Secure Deletion with SDelete","author":"Thomas Patzke","status":"test","level":"medium","date":"2017-06-14","modified":"2024-12-13","description":"Detects files that have extensions commonly seen while SDelete is used to wipe files.","references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/sdelete.htm","https://www.jpcert.or.jp/english/pub/sr/ir_research.html","https://learn.microsoft.com/en-gb/sysinternals/downloads/sdelete"],"logsource":{"product":"windows","service":"security"},"tags":["attack.impact","attack.stealth","attack.defense-impairment","attack.t1070.004","attack.t1027.005","attack.t1485","attack.t1553.002","attack.s0195"],"path":"rules/windows/builtin/security/win_security_sdelete_potential_secure_deletion.yml","techniques":["T1070.004","T1027.005","T1485","T1553.002"],"cves":[]},{"id":"6f8b3439-a203-45dc-a88b-abf57ea15ccf","title":"HackTool - CrackMapExec PowerShell Obfuscation","author":"Thomas Patzke","status":"test","level":"high","date":"2020-05-22","modified":"2023-02-21","description":"The CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.","references":["https://github.com/byt3bl33d3r/CrackMapExec","https://github.com/byt3bl33d3r/CrackMapExec/blob/0a49f75347b625e81ee6aa8c33d3970b5515ea9e/cme/helpers/powershell.py#L242"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.001","attack.t1027.005"],"path":"rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_powershell_obfuscation.yml","techniques":["T1059.001","T1027.005"],"cves":[]},{"id":"f0ca6c24-3225-47d5-b1f5-352bf07ecfa7","title":"PUA - DefenderCheck Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-30","modified":"2023-02-04","description":"Detects the use of DefenderCheck, a tool to evaluate the signatures used in Microsoft Defender. It can be used to figure out the strings / byte chains used in Microsoft Defender to detect a tool and thus used for AV evasion.","references":["https://github.com/matterpreter/DefenderCheck"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1027.005"],"path":"rules/windows/process_creation/proc_creation_win_pua_defendercheck.yml","techniques":["T1027.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}