Log Enumeration Followed by Log Clearing Within 10 Minutes
Detects instances where Windows event logs are cleared using built-in utilities (wevtutil.exe) or PowerShell (Get-EventLog/Get-WinEvent, Clear-EventLog) shortly after those same logs were queried or enumerated by the same user on the same device. This pattern is highly indicative of an adversary attempting to conceal malicious activity.
Microsoft Sentinel (KQL)

