1200KM / detection
T1685.001 Disable or Modify Windows Event Log — Detection Rules
Detection workspace for T1685.001 Disable or Modify Windows Event Log: 26 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- ETW Logging/Processing Option Disabled On IIS Server · test · medium · {"product":"windows","service":"iis-configuration"}
- HTTP Logging Disabled On IIS Server · test · high · {"product":"windows","service":"iis-configuration"}
- New Module Module Added To IIS Server · test · medium · {"product":"windows","service":"iis-configuration"}
- Previously Installed IIS Module Was Removed · test · low · {"product":"windows","service":"iis-configuration"}
- Windows Event Auditing Disabled · test · low · {"product":"windows","service":"security","definition":"dfd8c0f4-e6ad-4e07-b91b-f2fca0ddef64"}
- Important Windows Event Auditing Disabled · test · high · {"product":"windows","service":"security","definition":"dfd8c0f4-e6ad-4e07-b91b-f2fca0ddef64"}
- EVTX Created In Uncommon Location · test · medium · {"category":"file_event","product":"windows","definition":"Requirements: The \".evtx\" extension should be monitored via a Sysmon configuration. Example: <TargetFilename condition=\"end with\">.evtx<TargetFilename>"}
- HackTool - SharpEvtMute DLL Load · test · high · {"category":"image_load","product":"windows"}
- HackTool - SysmonEnte Execution · test · high · {"category":"process_access","product":"windows"}
- Suspicious Svchost Process Access · test · high · {"category":"process_access","product":"windows"}
- Audit Policy Tampering Via NT Resource Kit Auditpol · test · high · {"category":"process_creation","product":"windows"}
- Audit Policy Tampering Via Auditpol · test · high · {"category":"process_creation","product":"windows"}
- Windows EventLog Autologger Session Registry Modification Via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- Security Event Logging Disabled via MiniNt Registry Key - Process · experimental · high · {"category":"process_creation","product":"windows"}
- Filter Driver Unloaded Via Fltmc.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Sysmon Driver Unloaded Via Fltmc.EXE · test · high · {"product":"windows","category":"process_creation"}
- HackTool - SharpEvtMute Execution · test · high · {"product":"windows","category":"process_creation"}
- Disable Windows IIS HTTP Logging · test · high · {"category":"process_creation","product":"windows"}
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Eventlog Clearing or Configuration Change Activity · stable · high · {"category":"process_creation","product":"windows"}
- Disable Security Events Logging Adding Reg Key MiniNt · test · high · {"category":"registry_event","product":"windows"}
- Change Winevt Channel Access Permission Via Registry · test · high · {"category":"registry_set","product":"windows"}
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set · experimental · high · {"category":"registry_set","product":"windows"}
- Potential AutoLogger Sessions Tampering · test · high · {"category":"registry_set","product":"windows"}
- Disable Windows Event Logging Via Registry · test · high · {"category":"registry_set","product":"windows"}
- Potential EventLog File Location Tampering · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0187 Detect Disabled Windows Event Log
AN0535 Analytic 0535
Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.