Windows Event Log Clearing via wevtutil.exe (T1070.001)
Detects the use of the Windows command-line utility 'wevtutil.exe' to clear Windows event logs. Attackers often clear logs to hide evidence of post-compromise activity.
SentinelOne

Detects the use of the Windows command-line utility 'wevtutil.exe' to clear Windows event logs. Attackers often clear logs to hide evidence of post-compromise activity.

Already have an account?