Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0187 — Detect Disabled Windows Event Log
DET0187

Detect Disabled Windows Event Log

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0535 Analytic 0535
Windows

Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.

WinEventLog:System EventCode=7035 WinEventLog:Security EventCode=1102 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=1
[AuthorizedAdminAccounts] List of accounts authorized to legitimately modify audit policies or disable services.
[TimeWindow] Correlation window between registry modification, service stop, and audit policy commands.
[ServiceNames] Customizable set of monitored services such as EventLog, Sysmon, or custom loggers.

Detected Techniques

1

Details

MITRE ID
DET0187
STIX ID
x-mitre-detection-strategy--cfedfc6c-6e31-481b-be1e-e23a760fec44
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.