Windows Security Event Log Cleared
This rule detects when the Windows Security Event Log (Event ID 1102) has been cleared on a system. Clearing event logs is a common technique used by adversaries to remove traces of their activity and evade detection.
Microsoft Sentinel (KQL)

