<<< Hide Navigation Hide TOC >>>
Security Eventlog Cleared (d99b79d2-0a6f-4f46-ad8b-260b6e17f982)
One of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Security Eventlog Cleared (d99b79d2-0a6f-4f46-ad8b-260b6e17f982) | Sigma-Rules | Clear Windows Event Logs - T1070.001 (6495ae23-3ab4-43c5-a94f-5638a2c31fd2) | Attack Pattern | 1 |
Clear Windows Event Logs - T1070.001 (6495ae23-3ab4-43c5-a94f-5638a2c31fd2) | Attack Pattern | Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) | Attack Pattern | 2 |