Clear Windows Event Logs

T1685.005

Sub-technique of T1685 Disable or Modify Tools.View on attack.mitre.org

About this technique

Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit.

With administrator privileges, the event logs can be cleared with the following utility commands:

* `wevtutil cl system`
* `wevtutil cl application`
* `wevtutil cl security`

These logs may also be cleared through other mechanisms, such as the event viewer GUI or PowerShell. For example, adversaries may use the PowerShell command `Remove-EventLog -LogName Security` to delete the Security EventLog and after reboot, disable future logging. Note: events may still be generated and logged in the .evtx file between the time the command is run and the reboot.

Adversaries may also attempt to clear logs by directly deleting the stored log files within `C:\Windows\System32\winevt\logs\`.

Detection rules12

Rules on DetectionCode tagged with T1685.005.

Sigma7

RuleLevelLog source
Important Windows Eventlog Clearedhighwindows / NULL
Security Eventlog Clearedhighwindows / NULL
Suspicious Eventlog Clearing or Configuration Change Activityhighwindows / process_creation
Suspicious Windows Trace ETW Session Tamper Via Logman.EXEhighwindows / process_creation
Eventlog Clearedmediumwindows / NULL
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLogmediumwindows / NULL
Suspicious Eventlog Clearmediumwindows / ps_script

Splunk5

RuleTypeRiskData source
Disable Logs Using WevtUtilTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious wevtutil UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Event Log ClearedTTPNULLWindows Event Log Security 1102, Windows Event Log System 104
Windows Event Logging Service Has ShutdownHuntingNULLWindows Event Log Security 1100
Windows Eventlog Cleared Via WevtutilAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups14

Software26

Show 2 more

Campaigns2

Procedure examples42

Groups14

Used byProcedure example
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

GroupAPT32

APT32 has cleared select event log entries.

GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

GroupAPT41

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.

GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

GroupChimera

Chimera has cleared event logs on compromised hosts.

GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

GroupFIN5

FIN5 has cleared event logs from victims.

View all 14 groups examples

Software26

Used byProcedure example
MalwareApostle

Apostle will attempt to delete all event logs on a victim machine following file wipe activity.

MalwareBlackCat

BlackCat can clear Windows event logs using `wevtutil.exe`.

MalwareBlackEnergy

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.

MalwareDUSTTRAP

DUSTTRAP can delete infected system log information.

MalwareFinFisher

FinFisher clears the system event logs using OpenEventLog/ClearEventLog APIs .

Malwaregh0st RAT

gh0st RAT is able to wipe event logs.

MalwareHermeticWiper

HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system.

MalwareHermeticWizard

HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.

View all 26 software examples

Campaigns2

Used byProcedure example
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise.

CampaignOperation Wocao

During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`.

References1

  1. disable_win_evt_logging Open source
    Heiligenstein, L. (n.d.). REP-25: Disable Windows Event Logging. Retrieved April 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.