Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0532 — Detection of Event Log Clearing on Windows via Behavioral Chain
DET0532

Detection of Event Log Clearing on Windows via Behavioral Chain

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1472 Analytic 1472
Windows

Detects behavioral sequence where an adversary gains elevated privileges and clears event logs using native binaries (e.g., wevtutil), PowerShell, or direct file deletion of .evtx files.

WinEventLog:Security EventCode=1102 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=23
[TimeWindow] Time range between log-clearing command and 1102 event; tunable to reduce false positives
[UserContext] Filter by admin/elevated users; allow tuning to detect abuse of high-privilege accounts
[CommandLinePattern] Match common variations of log-clearing commands like `Remove-EventLog`, `wevtutil cl`
[TargetLogName] Scope detection to Security, System, Application, or custom logs based on environment

Detected Techniques

1

Details

MITRE ID
DET0532
STIX ID
x-mitre-detection-strategy--d340864e-5685-48d5-8a78-3c55a7169207
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.