Windows Event Log Cleared
This rule detects when Windows Security or System event logs are cleared. Adversaries often clear event logs to remove evidence of their activities after gaining access to a system.
Microsoft Sentinel (KQL)

This rule detects when Windows Security or System event logs are cleared. Adversaries often clear event logs to remove evidence of their activities after gaining access to a system.

Already have an account?