Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685.005 Clear Windows Event Logs |
GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
| T1685.005 Clear Windows Event Logs |
GroupIndrik Spider | Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`. |
| T1685.005 Clear Windows Event Logs |
GroupVolt Typhoon | Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity. |
| T1685.005 Clear Windows Event Logs |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events. |
| T1685.005 Clear Windows Event Logs |
GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| T1685.005 Clear Windows Event Logs |
GroupAPT32 | APT32 has cleared select event log entries. |
| T1685.005 Clear Windows Event Logs |
GroupHAFNIUM | HAFNIUM has cleared actor-performed actions from logs. |
| T1685.005 Clear Windows Event Logs |
GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
| T1685.005 Clear Windows Event Logs |
GroupFIN5 | FIN5 has cleared event logs from victims. |
| T1685.005 Clear Windows Event Logs |
GroupChimera | Chimera has cleared event logs on compromised hosts. |
| T1685.005 Clear Windows Event Logs |
GroupMirrorFace | MirrorFace has deleted Windows event logs. |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
| T1685.005 Clear Windows Event Logs |
GroupFIN8 | FIN8 has cleared logs during post compromise cleanup activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.