Windows Event Log Cleared

Description

This search looks for Windows events that indicate one of the Windows event logs has been purged.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Advanced Threat Detection

Category

Endpoint Compromise

Alert Volume

This search looks for Windows events that indicate one of the Windows event logs has been purged.

SPL Difficulty

None

Journey

Stage 1

MITRE ATT&CK Tactics

Defense Evasion

MITRE ATT&CK Techniques

Indicator Removal on Host

Clear Windows Event Logs

MITRE Threat Groups

APT28
APT32
APT38
APT41
Dragonfly 2.0
FIN5
FIN8

Kill Chain Phases

Actions On Objectives

Data Sources

Windows Security

   Help

Windows Event Log Cleared Help

To successfully implement this search, you need to be ingesting Windows event logs from your hosts.

   Search

Open in Search