Title:Potential EventLog File Location Tampering Status:test Description:Detects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting References: -https://learn.microsoft.com/en-us/windows/win32/eventlog/eventlog-key Author: D3F7A5105 Date: 2023-01-02 modified:2023-08-17 Tags:
-'attack.defense-impairment'
-'attack.t1685.001'
Logsource:
category: registry_set
product: windows
Detection: selection: TargetObject|contains:
'\SYSTEM\CurrentControlSet\Services\EventLog\' TargetObject|endswith:
'\File' filter: Details|contains:
'\System32\Winevt\Logs\' condition:selection and not filter Falsepositives:
-Unknown Level:high