T1070.001 Windows Event Log Clearing via wevtutil or PowerShell

Detects attempts to clear Windows event logs using the native command-line utility 'wevtutil' or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their activities from security, system, and application logs. The rule includes exclusions for common administrative, backup, and security-related processes to minimize false positives.