Title:
Important Windows Eventlog Cleared
Status:
test
Description:Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by "wevtutil cl" command execution
References:
-https://twitter.com/deviouspolack/status/832535435960209408
-https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100
Author: Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-05-17
modified:2023-11-15
Tags:
- -'attack.defense-impairment'
- -'attack.t1685.005'
- -'car.2016-04-002'
Logsource:
- product: windows
- service: system
Detection:
selection:
EventID:
'104'
Provider_Name:
'Microsoft-Windows-Eventlog'
Channel:
-'Microsoft-Windows-PowerShell/Operational'
-'Microsoft-Windows-Sysmon/Operational'
-'PowerShellCore/Operational'
-'Security'
-'System'
-'Windows PowerShell'
condition:
selection
Falsepositives:
-Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
-System provisioning (system reset before the golden image creation)
Level:
high