T1685.005 Clear Windows Event Logs
Subtécnica de T1685 Disable or Modify Tools
Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit. With administrator privileges, the event logs can be cleared with the…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- NotPetya Ransomware Activitycriticaltest · windows
- Suspicious Eventlog Clearing or Configuration Change Activityhighstable · windows
- Important Windows Eventlog Clearedhightest · windows
- Security Eventlog Clearedhightest · windows
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXEhightest · windows
- Eventlog Clearedmediumtest · windows
- Failed Event Log Clear Via WMI NTEventLogFile ClearEventLogmediumtest · windows
- Suspicious Eventlog Clearmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.