Tag
medium
advisory
Suspicious wevtutil.exe Usage for Event Log Clearing
1 rule 1 TTPAttackers frequently abuse the built-in 'wevtutil.exe' utility to clear Windows event logs, a common defense evasion technique used to disrupt forensic investigations and hide post-compromise activity.
defense-evasion
log-manipulation
windows-security
1r
1t
high
advisory
Suspicious Wevtutil Usage for Clearing Windows Event Logs
2 rulesDetection of wevtutil.exe being used with parameters to clear event logs, indicating potential attempts to evade detection and hinder forensic investigations by adversaries.
Splunk Enterprise +2
defense-evasion
windows
log-manipulation
2r