Tag
high
advisory
Windows Event Log Cleared
2 rules 1 TTPDetection of Windows event log clearing using Event IDs 1102 (Security) or 104 (System) which may indicate an attempt to hide malicious activity and impede forensic investigation.
Windows
defense-evasion
event-logs
2r
1t
low
advisory
Windows Event Log Clearing Attempt Detected
3 rules 1 TTPAdversaries clear Windows event logs to evade detection and destroy forensic evidence, breaking SIEM detections and covering their tracks.
Windows
defense-evasion
event-logs
3r
1t
high
advisory
Windows Eventlog Cleared Via Wevtutil
2 rules 1 TTPAdversaries may clear Windows event logs using `wevtutil.exe` to remove evidence of their activity and hinder forensic investigations.
Splunk Enterprise +2
defense-evasion
windows
event-logs
2r
1t
low
advisory
Windows Event Log Clearing Detected
2 rules 2 TTPsThis threat brief covers the detection of adversaries clearing or disabling Windows event logs, a common defense evasion tactic, using tools like wevtutil.exe and PowerShell cmdlets to remove evidence of their activities.
Windows
defense-evasion
event-logs
2r
2t