Windows Event Log was cleared using wevtutil.exe
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Inhibit System Recovery (T1490)
Severity
Low
Description
A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis.
Attacker's Goals
Delete logs to cover tracks of the malicious activity, making it harder to perform analysis.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Variations
PreviousWindows CGO, actor process and action module with anomalous characteristics
NextWindows event logs were cleared with PowerShell
Was this helpful?
