Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF030.003
- Created: 03rd August 2026
- Updated: 03rd August 2026
- Contributor: The ITM Team
Use of Disappearing or Self-Deleting Messages
A subject enables or uses a communication feature that automatically deletes messages after they are read, after a defined period, or when a conversation is closed, with the intention of reducing the communication evidence available to investigators.
The subject may use disappearing-message functionality within an approved corporate platform or through a non-corporate messaging application. Automatic deletion may be configured for an individual conversation, group, channel, workspace, or account. The subject may also change an existing conversation from persistent retention to temporary retention before exchanging information connected to an infringement.
This behavior differs from the manual deletion of corporate or non-corporate messages because the removal mechanism is established before or during the communication. Messages may disappear without a separate deletion action being performed after each message is sent.
Investigators should examine when the disappearing-message setting was enabled, who enabled it, the configured retention period, which participants were involved, and whether the setting was changed shortly before sensitive or suspicious communications occurred. The ordinary availability of an ephemeral messaging feature does not establish anti-forensic intent; classification should require evidence that the feature was deliberately used to reduce investigative visibility.