{"id":"T1070.007","name":"Clear Network Connection History and Configurations","url":"https://attack.mitre.org/techniques/T1070/007","tactics":["stealth"],"platforms":["Linux","macOS","Windows","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0049","stix_id":"x-mitre-detection-strategy--45ac24cf-b8f4-44d5-97e1-3efe2bf28abc","name":"Behavioral Detection of Network History and Configuration Tampering","url":"https://attack.mitre.org/detectionstrategies/DET0049","analytics":[{"id":"AN0133","stix_id":"x-mitre-analytic--d71c4839-8d23-41f4-b59a-8bd2c3517d1e","name":"Analytic 0133","description":"Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys).","url":"https://attack.mitre.org/detectionstrategies/DET0049#AN0133","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:cli","channel":"Command Line Telemetry","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"edr-cli"},{"name":"WinEventLog:Security","channel":"Firewall Rule Modification","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TargetPathRegex","description":"Filter file/registry paths like *\\Terminal Server Client\\* or *Default.rdp*"},{"field":"TimeWindow","description":"Correlate command/registry edits within close proximity to suspicious connection activity"},{"field":"UserContext","description":"Detect cleanup behavior from non-interactive or SYSTEM accounts"}],"live":true,"detection_strategies":["DET0049"],"techniques":["T1070.007"]},{"id":"AN0134","stix_id":"x-mitre-analytic--0bd02555-3b54-4425-84c8-118b95857df1","name":"Analytic 0134","description":"Detects deletion or overwriting of logs/configs that store SSH or proxy activity, such as /var/log/auth.log or custom .bash_history clearing tied to SSH sessions or firewall rule changes.","url":"https://attack.mitre.org/detectionstrategies/DET0049#AN0134","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"PATH","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"CommandMatchPattern","description":"Commands like `> /var/log/auth.log`, `rm ~/.bash_history`, `iptables -F`"},{"field":"LogPathFilter","description":"Focus on /var/log/auth.log, /etc/ssh/, ~/.bash_history"}],"live":true,"detection_strategies":["DET0049"],"techniques":["T1070.007"]},{"id":"AN0135","stix_id":"x-mitre-analytic--d01951d8-aae8-48b6-afd3-68c86fc167b1","name":"Analytic 0135","description":"Detects removal of Remote Login or Screen Sharing logs in Unified Logging, deletion of `com.apple.UTun`, or suspicious Terminal use of `rm`, `sudo pfctl -F all` to clear network state/config history.","url":"https://attack.mitre.org/detectionstrategies/DET0049#AN0135","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream --predicate 'eventMessage contains \"loginwindow\" or \"pfctl\"'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"FilenameMatch","description":"e.g., *com.apple.UTun*, *RemoteManagement* log files"},{"field":"TimeDeltaFromLogin","description":"Correlate deletion with recent SSH or GUI remote login session"}],"live":true,"detection_strategies":["DET0049"],"techniques":["T1070.007"]},{"id":"AN0136","stix_id":"x-mitre-analytic--5258feec-def7-43e0-bbe9-459ba53d3e28","name":"Analytic 0136","description":"Detects firewall rule modifications or reset of logs/connection tables (e.g., `clear logging`, `erase startup-config`, `write erase`) following remote access activity on routers, switches, or VPN appliances.","url":"https://attack.mitre.org/detectionstrategies/DET0049#AN0136","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"Command Audit / Configuration Change","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"Session History Reset","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"CommandPattern","description":"e.g., `clear logging`, `no logging buffered`, `no ip domain-lookup`"},{"field":"DeviceTypeFilter","description":"Switches vs VPN vs routers"}],"live":true,"detection_strategies":["DET0049"],"techniques":["T1070.007"]}],"live":true,"version":"1.0","techniques":["T1070.007"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}