Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1027.005 — Indicator Removal from Tools
T1027.005

Indicator Removal from Tools

Stealth
TLP:CLEAR

Description

Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify the tool by removing the indicator and using the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may modify the file to explicitly avoid that signature, and then re-use the malware.

MITRE ATT&CK Detection Strategies
1

DET0189 Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification
AN0540 Windows

Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).

WinEventLog:Application WinEventLog:Sysmon WinEventLog:Sysmon
AN0542 macOS

Detection of XProtect or AV quarantining a known tool, followed by modification (file size, hash, string) and subsequent re-execution by the same or related user.

macos:unifiedlog macos:osquery
AN0541 Linux

Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain.

auditd:SYSCALL auditd:SYSCALL linux:osquery EDR:detection

Details

Platforms
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.