Clear Network Connection History and Configurations

T1070.007

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as various artifacts that highlight connection history may be created on a system and/or in application logs from behaviors that require network connections, such as Remote Services or External Remote Services. Defenders may use these artifacts to monitor or otherwise analyze network connections created by adversaries.

Network connection history may be stored in various locations. For example, RDP connection history may be stored in Windows Registry values under :

* HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default
* HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers

Windows may also store information about recent RDP connections in files such as C:\Users\\%username%\Documents\Default.rdp and `C:\Users\%username%\AppData\Local\Microsoft\Terminal
Server Client\Cache\`. Similarly, macOS and Linux hosts may store information highlighting connection history in system logs (such as those stored in `/Library/Logs` and/or `/var/log/`).

Malicious network connections may also require changes to third-party applications or network configuration settings, such as Disable or Modify System Firewall or tampering to enable Proxy. Adversaries may delete or modify this data to conceal indicators and/or impede defensive analysis.

Detection rules0

Rules on DetectionCode tagged with T1070.007.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software1

Campaigns1

Procedure examples4

Groups2

Used byProcedure example
GroupUNC3886

UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources.

GroupVolt Typhoon

Volt Typhoon has inspected server logs to remove their IPs.

Software1

Used byProcedure example
MalwareSUNBURST

SUNBURST also removed the firewall rules it created during execution.

Campaigns1

Used byProcedure example
CampaignRedPenguin

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

References5

  1. Apple Culprit Access Open source
    rjben. (2012, May 30). How do you find the culprit when unauthorized access to a computer is a problem?. Retrieved August 3, 2022.
  2. Apple Unified Log Analysis Remote Login and Screen Sharing Open source
    Sarah Edwards. (2020, April 30). Analysis of Apple Unified Logs: Quarantine Edition [Entry 6] – Working From Home? Remote Logins. Retrieved August 19, 2021.
  3. FreeDesktop Journal Open source
    freedesktop.org. (n.d.). systemd-journald.service. Retrieved June 15, 2022.
  4. Microsoft RDP Removal Open source
    Microsoft. (2021, September 24). How to remove entries from the Remote Desktop Connection Computer box. Retrieved June 15, 2022.
  5. Moran RDPieces Open source
    Moran, B. (2020, November 18). Putting Together the RDPieces. Retrieved October 17, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.