Potential EventLog File Location Tampering

 Original Source: [Sigma source]
Title: Potential EventLog File Location Tampering
Status: test
Description:Detects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting
References:
  -https://learn.microsoft.com/en-us/windows/win32/eventlog/eventlog-key
Author: D3F7A5105
Date: 2023-01-02
modified:2023-08-17
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\SYSTEM\CurrentControlSet\Services\EventLog\'
    TargetObject|endswith: '\File'
  filter:
    Details|contains: '\System32\Winevt\Logs\'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high