ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1685.005×

14 examples

TechniqueUsed byProcedure example
T1685.005
Clear Windows Event Logs
GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

T1685.005
Clear Windows Event Logs
GroupIndrik Spider

Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`.

T1685.005
Clear Windows Event Logs
GroupVolt Typhoon

Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.

T1685.005
Clear Windows Event Logs
GroupAPT41

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.

T1685.005
Clear Windows Event Logs
GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

T1685.005
Clear Windows Event Logs
GroupAPT32

APT32 has cleared select event log entries.

T1685.005
Clear Windows Event Logs
GroupHAFNIUM

HAFNIUM has cleared actor-performed actions from logs.

T1685.005
Clear Windows Event Logs
GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

T1685.005
Clear Windows Event Logs
GroupFIN5

FIN5 has cleared event logs from victims.

T1685.005
Clear Windows Event Logs
GroupChimera

Chimera has cleared event logs on compromised hosts.

T1685.005
Clear Windows Event Logs
GroupMirrorFace

MirrorFace has deleted Windows event logs.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

T1685.005
Clear Windows Event Logs
GroupFIN8

FIN8 has cleared logs during post compromise cleanup activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.