Windows Security Audit Log Cleared - Potential Evidence Destruction

This rule detects when the Windows Security Event Log has been cleared, which is often an indicator that an adversary is attempting to hide their tracks and remove evidence of unauthorized activities on a system.