Esc
Object Eviction
Definition
Terminate or remove an object from a host machine. This is the broadest class for object eviction.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 9 techniques in this category, Object Eviction.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Object Eviction | D3-OE | Terminate or remove an object from a host machine. This is the broadest class for object eviction. | |
| - File Eviction | D3-FEV | File eviction techniques delete files from system storage. | |
| - Disk Partitioning | D3-DKP | Disk Partitioning is the process of dividing a disk into multiple distinct sections, known as partitions. | |
| - Domain Registration Takedown | D3-DRT | The process of performing a takedown of the attacker's domain registration infrastructure. | |
| - DNS Cache Eviction | D3-DNSCE | Flushing DNS to clear any IP addresses or other DNS records from the cache. | Flush DNS Cache |
| - Disk Formatting | D3-DKF | Disk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB flash drive, for initial use. | |
| - Disk Erasure | D3-DKE | Disk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means. | |
| - Registry Key Deletion | D3-RKD | Delete a registry key. | |
| - Email Removal | D3-ER | The email removal technique deletes email files from system storage. | Email Deletion |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Discovery
File and Directory Discovery
System Network Configuration Discovery
System Owner/User Discovery
Remote System Discovery
Cloud Storage Object Discovery
Collection
Email Collection
Archive Collected Data
Data from Local System
Automated Collection
Data Staged
Persistence
Office Application Startup
Event Triggered Execution
Modify Authentication Process
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Server Software Component
Execution
Command and Scripting Interpreter
Hijack Execution Flow
Scheduled Task/Job
Trusted Developer Utilities Proxy Execution
User Execution
Software Deployment Tools
Stealth
XSL Script Processing
Process Injection
System Binary Proxy Execution
Hijack Execution Flow
Rootkit
Masquerading
Obfuscated Files or Information
Hide Artifacts
Impair Defenses
Trusted Developer Utilities Proxy Execution
Deobfuscate/Decode Files or Information
Indicator Removal
Privilege Escalation
Event Triggered Execution
Process Injection
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Abuse Elevation Control Mechanism
Credential Access
Modify Authentication Process
Credentials from Password Stores
OS Credential Dumping
Forced Authentication
Unsecured Credentials
Steal or Forge Authentication Certificates
Defense Impairment
Modify Authentication Process
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Lateral Movement
Internal Spearphishing
Software Deployment Tools
Impact
Data Manipulation
Data Encrypted for Impact
Disk Wipe