Settra Ransomware Misspelled wevtutil Defender Log Clear Command
Detects the use of the 'wevtutil.exe' command to clear Windows Event Logs where the command specifies a misspelled event log name, 'Microsoft-Windows-Defender/Operational' instead of the correct 'Microsoft-Windows-Windows-Defender/Operational'. This specific spelling error is associated with the Settra ransomware and indicates an unsuccessful attempt to clear Windows Defender logs.
Sigma

