Windows Security Event Log Cleared

This rule detects when the Windows Security Event Log (Event ID 1102) has been cleared on a system. Clearing event logs is a common technique used by adversaries to remove traces of their activity and evade detection.