{"id":"T1070.009","name":"Clear Persistence","url":"https://attack.mitre.org/techniques/T1070/009","tactics":["stealth"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0040","stix_id":"x-mitre-detection-strategy--80eb76bc-6599-4adf-8d8c-8126e7e63d12","name":"Detection of Persistence Artifact Removal Across Host Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0040","analytics":[{"id":"AN0113","stix_id":"x-mitre-analytic--5882d2ff-289e-454d-9146-81306c154be3","name":"Analytic 0113","description":"Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`.","url":"https://attack.mitre.org/detectionstrategies/DET0040#AN0113","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4726, 4657","data_component":"DC0009","data_component_name":"User Account Deletion","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:TaskScheduler","channel":"EventCode=106","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-taskscheduler"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TargetRegistryPathRegex","description":"Filters known persistence keys like Run/RunOnce, Image File Execution Options"},{"field":"DeletedScheduledTaskName","description":"Monitors known or suspicious task names deleted post-persistence"},{"field":"DeletedAccountGroupScope","description":"Focuses on highly privileged or recently created accounts"}],"live":true,"detection_strategies":["DET0040"],"techniques":["T1070.009"]},{"id":"AN0114","stix_id":"x-mitre-analytic--83a2f3c2-24c5-466d-8453-aa52802c2991","name":"Analytic 0114","description":"Detects removal of persistence artifacts such as crontab entries, systemd service units, and malicious user accounts through commands like `crontab -r`, `rm /etc/systemd/system/*.service`, or `userdel`.","url":"https://attack.mitre.org/detectionstrategies/DET0040#AN0114","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"file deletion","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ServicePathMatch","description":"Targets suspicious or orphaned unit files in /etc/systemd/system/"},{"field":"CronUserScope","description":"Focus on crontab activity from root or uncommon users"},{"field":"UserDeletionActivity","description":"Looks for userdel or passwd deletion"}],"live":true,"detection_strategies":["DET0040"],"techniques":["T1070.009"]},{"id":"AN0115","stix_id":"x-mitre-analytic--81d64cae-ddd2-4512-9c8a-9a574b968c52","name":"Analytic 0115","description":"Detects deletion of launch agents (~/Library/LaunchAgents/) and launch daemons (/Library/LaunchDaemons/), especially after suspicious process execution or when tied to known persistence methods.","url":"https://attack.mitre.org/detectionstrategies/DET0040#AN0115","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"LaunchDaemonPath","description":"Common plist file paths for persistence: ~/Library/LaunchAgents/*.plist"},{"field":"CorrelatedProcessImage","description":"Ties deletion to parent process (e.g., suspicious AppleScript runner)"}],"live":true,"detection_strategies":["DET0040"],"techniques":["T1070.009"]},{"id":"AN0116","stix_id":"x-mitre-analytic--c6ae166f-f2ac-405a-85c2-b7f9349a1b99","name":"Analytic 0116","description":"Detects adversary removal of persistence implants (e.g., rc.local entries or crontab injections) via CLI (`rm`, `sed`, `crontab -r`) and deletion of startup or management scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0040#AN0116","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"/var/log/vmkernel.log","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-vmkernel"},{"name":"esxi:shell","channel":"shell history","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"ScriptRemovalPath","description":"e.g., /etc/rc.local, /etc/init.d/custom.sh"},{"field":"StartupEntryClearance","description":"Wipe or truncate of persistence locations"}],"live":true,"detection_strategies":["DET0040"],"techniques":["T1070.009"]}],"live":true,"version":"1.0","techniques":["T1070.009"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}