• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Windows Event Log Cleared

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ethan Andrews@eandrews
    •updated Jun 8, 2026•3•0•12

    This rule detects when Windows Security or System event logs are cleared. Adversaries often clear event logs to remove evidence of their activities after gaining access to a system.

    Microsoft Sentinel (KQL)

    Tags

    T1070.001 - Clear Windows Event LogsTA0005 - Defense EvasionLog ClearedWindowsWindows Eventlog SecurityWindows Eventlog Systemkql

    Found in

    • Evolution Analysis of Grixba Infostealer ToolLast updated Jun 8, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?