{"id":"d99b79d2-0a6f-4f46-ad8b-260b6e17f982","title":"Security Eventlog Cleared","description":"One of the Windows Eventlogs has been cleared. e.g. caused by \"wevtutil cl\" command execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-01-10","modified":"2022-02-24","tags":["attack.defense-impairment","attack.t1685.005","car.2016-04-002"],"technique_ids":["T1685.005"],"logsource":{"product":"windows","service":"security"},"falsepositives":["Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)","System provisioning (system reset before the golden image creation)"],"references":["https://twitter.com/deviouspolack/status/832535435960209408","https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100","https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml"],"source_path":"rules/windows/builtin/security/win_security_audit_log_cleared.yml","source_sha256":"ac270c491cfcd9f5ed3b69f3d7cd73b7e87166d761ca0b5ded4238e5117476b9","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/security/win_security_audit_log_cleared.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Security Eventlog Cleared\nid: d99b79d2-0a6f-4f46-ad8b-260b6e17f982\nrelated:\n    - id: f2f01843-e7b8-4f95-a35a-d23584476423\n      type: obsolete\n    - id: a122ac13-daf8-4175-83a2-72c387be339d\n      type: obsolete\nstatus: test\ndescription: One of the Windows Eventlogs has been cleared. e.g. caused by \"wevtutil cl\" command execution\nreferences:\n    - https://twitter.com/deviouspolack/status/832535435960209408\n    - https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100\n    - https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml\nauthor: Florian Roth (Nextron Systems)\ndate: 2017-01-10\nmodified: 2022-02-24\ntags:\n    - attack.defense-impairment\n    - attack.t1685.005\n    - car.2016-04-002\nlogsource:\n    product: windows\n    service: security\ndetection:\n    selection_517:\n        EventID: 517\n        Provider_Name: Security\n    selection_1102:\n        EventID: 1102\n        Provider_Name: Microsoft-Windows-Eventlog\n    condition: 1 of selection_*\nfalsepositives:\n    - Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)\n    - System provisioning (system reset before the golden image creation)\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1685.005","id":"T1685.005","name":"Clear Windows Event Logs","page":"techniques/enterprise/T1685.005/"}],"data_path":"data/detection-rules/d99b79d2-0a6f-4f46-ad8b-260b6e17f982.json","kind":"sigma"}
