Windows Event Log Clearing via wevtutil or PowerShell in Network Traffic
Detects clear-text attempts to clear Windows Event Logs using 'wevtutil' or 'Clear-EventLog' command patterns within network traffic, indicating a potential attempt to remove evidence of malicious activity on a host.
Suricata

