{"id":"T1070.010","name":"Relocate Malware","url":"https://attack.mitre.org/techniques/T1070/010","tactics":["stealth"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0439","stix_id":"x-mitre-detection-strategy--3fa3299e-a8c2-4555-890b-544314ae1e44","name":"Detection of Malware Relocation via Suspicious File Movement","url":"https://attack.mitre.org/detectionstrategies/DET0439","analytics":[{"id":"AN1216","stix_id":"x-mitre-analytic--143f3057-237e-427f-911a-2aa7d64721f0","name":"Analytic 1216","description":"Detects the relocation of malicious executables via copy/move actions across suspicious folders (e.g., from Downloads to System32), followed by deletion of the original source or renaming to blend into legitimate binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0439#AN1216","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=23","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SuspiciousTargetPathRegex","description":"Patterns like \\Windows\\*, \\System32\\*, or temp+execution directories"},{"field":"TimeWindow","description":"Correlate copy+rename+delete chains within 5-minute window"},{"field":"FileExtensionFilter","description":"Limit to .exe, .dll, .js, .bat unless context suggests otherwise"}],"live":true,"detection_strategies":["DET0439"],"techniques":["T1070.010"]},{"id":"AN1217","stix_id":"x-mitre-analytic--39aa9168-6f3b-4179-84f9-a6b8dcf90900","name":"Analytic 1217","description":"Detects binary movement or copying between untrusted and trusted paths (e.g., /tmp/ → /usr/bin/ or /etc/init.d/) that may indicate persistence attempts or cleanup of origin traces.","url":"https://attack.mitre.org/detectionstrategies/DET0439#AN1217","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"PATH","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"RelocationPathPatterns","description":"Match movement into known persistence or exclusion directories"},{"field":"BinaryEntropyThreshold","description":"Apply threshold to detect high-entropy relocations (e.g., packed malware)"}],"live":true,"detection_strategies":["DET0439"],"techniques":["T1070.010"]},{"id":"AN1218","stix_id":"x-mitre-analytic--72540cd1-3ba6-4a4a-8866-a3113094196a","name":"Analytic 1218","description":"Detects movement of binaries to `~/Library/`, `/System/`, or app bundle locations, especially after initial execution or download from Safari or Mail.","url":"https://attack.mitre.org/detectionstrategies/DET0439#AN1218","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"TargetBundlePathPattern","description":"Monitor relocation to .app/Contents/MacOS/ or ~/Library/Launch*"},{"field":"QuarantineFlagCheck","description":"Check for disappearance of com.apple.quarantine attribute post-move"}],"live":true,"detection_strategies":["DET0439"],"techniques":["T1070.010"]},{"id":"AN1219","stix_id":"x-mitre-analytic--6b8a97fe-4e51-4409-9eab-f2795eb2ec74","name":"Analytic 1219","description":"Detects firmware or script relocation attempts (e.g., CLI-based `copy`, `move`, or `rename`) between temporary partitions and config startup folders on routers or switches.","url":"https://attack.mitre.org/detectionstrategies/DET0439#AN1219","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"command audit","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"StartupConfigPath","description":"Targeted config folders like flash:/startup-config or nvram:"},{"field":"CommandPatternMatch","description":"e.g., `copy tftp flash`, `rename`, `move flash:/old.bin flash:/new.bin`"}],"live":true,"detection_strategies":["DET0439"],"techniques":["T1070.010"]}],"live":true,"version":"1.0","techniques":["T1070.010"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}