Bulk Windows Event Log Clearing via wevtutil cl (Settra Ransomware)
Detects the execution of the Windows Event Utility (wevtutil.exe) with the 'cl' (clear-log) command, specifically targeting multiple critical event logs simultaneously. This behavior is indicative of anti-forensic activity aimed at obfuscating post-compromise actions, as seen in the Settra ransomware campaign.
Sigma

