Suspicious Use of PsLogList (aae1243f-d8af-40d8-ab20-33fc6d0c55bc)
Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs