Mass Windows Event Log Channel Disabling via Registry (DeadLock Anti-Forensics Pattern)

This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.