{"id":"100ef69e-3327-481c-8e5c-6d80d9507556","title":"Important Windows Eventlog Cleared","description":"Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by \"wevtutil cl\" command execution","author":"Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-05-17","modified":"2023-11-15","tags":["attack.defense-impairment","attack.t1685.005","car.2016-04-002"],"technique_ids":["T1685.005"],"logsource":{"product":"windows","service":"system"},"falsepositives":["Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)","System provisioning (system reset before the golden image creation)"],"references":["https://twitter.com/deviouspolack/status/832535435960209408","https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100"],"source_path":"rules/windows/builtin/system/microsoft_windows_eventlog/win_system_susp_eventlog_cleared.yml","source_sha256":"7815bfc6de0e8ea2eca76722b02177955737f865a3f477890e298163df2bc30c","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/microsoft_windows_eventlog/win_system_susp_eventlog_cleared.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Important Windows Eventlog Cleared\nid: 100ef69e-3327-481c-8e5c-6d80d9507556\nrelated:\n    - id: a62b37e0-45d3-48d9-a517-90c1a1b0186b\n      type: derived\nstatus: test\ndescription: Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by \"wevtutil cl\" command execution\nreferences:\n    - https://twitter.com/deviouspolack/status/832535435960209408\n    - https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100\nauthor: Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)\ndate: 2022-05-17\nmodified: 2023-11-15\ntags:\n    - attack.defense-impairment\n    - attack.t1685.005\n    - car.2016-04-002\nlogsource:\n    product: windows\n    service: system\ndetection:\n    selection:\n        EventID: 104\n        Provider_Name: 'Microsoft-Windows-Eventlog'\n        Channel:\n            - 'Microsoft-Windows-PowerShell/Operational'\n            - 'Microsoft-Windows-Sysmon/Operational'\n            - 'PowerShellCore/Operational'\n            - 'Security'\n            - 'System'\n            - 'Windows PowerShell'\n    condition: selection\nfalsepositives:\n    - Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)\n    - System provisioning (system reset before the golden image creation)\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1685.005","id":"T1685.005","name":"Clear Windows Event Logs","page":"techniques/enterprise/T1685.005/"}],"data_path":"data/detection-rules/100ef69e-3327-481c-8e5c-6d80d9507556.json","kind":"sigma"}
