Ransomware Series: Disabling or Clearing of Windows Security/System Event Logs

Detects attempts by an adversary to disable or clear Windows Event logs using standard administrative utilities such as wevtutil, PowerShell, auditpol, net, sc, or wmic to cover tracks or hinder forensic analysis.