Disable or Modify Windows Event Log

T1685.001

Sub-technique of T1685 Disable or Modify Tools.View on attack.mitre.org

About this technique

Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation. This data is used by security tools and analysts to generate detections.

The EventLog service maintains event logs from various system components and applications. By default, the service automatically starts when a system powers on. An audit policy, maintained by the Local Security Policy (secpol.msc), defines which system events the EventLog service logs. Security audit policy settings can be changed by running secpol.msc, then navigating to `Security Settings\Local Policies\Audit Policy` for basic audit policy settings or `Security Settings\Advanced Audit Policy Configuration` for advanced audit policy settings. `auditpol.exe` may also be used to set audit policies.

Adversaries may target system-wide logging or just that of a particular application. For example, the Windows EventLog service may be disabled using the `Set-Service -Name EventLog -Status Stopped` or `sc config eventlog start=disabled` commands (followed by manually stopping the service using `Stop-Service -Name EventLog`). Additionally, the service may be disabled by modifying the "Start" value in `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog` then restarting the system for the change to take effect.

There are several ways to disable the EventLog service via registry key modification. Without Administrator privileges, adversaries may modify the "Start" value in the key `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Security`, then reboot the system to disable the Security EventLog. With Administrator privilege, adversaries may modify the same values in `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System` and `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-Application` to disable the entire EventLog.

Additionally, adversaries may use `auditpol` and its sub-commands in a command prompt to disable auditing or clear the audit policy. To enable or disable a specified setting or audit category, adversaries may use the `/success` or `/failure` parameters. For example, `auditpol /set /category:"Account Logon" /success:disable /failure:disable` turns off auditing for the Account Logon category. To clear the audit policy, adversaries may run the following lines: `auditpol /clear /y` or `auditpol /remove /allusers`.

Detection rules39

Rules on DetectionCode tagged with T1685.001.

Sigma26

RuleLevelLog source
Audit Policy Tampering Via Auditpolhighwindows / process_creation
Audit Policy Tampering Via NT Resource Kit Auditpolhighwindows / process_creation
Change Winevt Channel Access Permission Via Registryhighwindows / registry_set
Disable Security Events Logging Adding Reg Key MiniNthighwindows / registry_event
Disable Windows Event Logging Via Registryhighwindows / registry_set
Disable Windows IIS HTTP Logginghighwindows / process_creation
HackTool - SharpEvtMute DLL Loadhighwindows / image_load
HackTool - SharpEvtMute Executionhighwindows / process_creation
HackTool - SysmonEnte Executionhighwindows / process_access
HTTP Logging Disabled On IIS Serverhighwindows / NULL
Important Windows Event Auditing Disabledhighwindows / NULL
Potential AutoLogger Sessions Tamperinghighwindows / registry_set
Potential EventLog File Location Tamperinghighwindows / registry_set
Security Event Logging Disabled via MiniNt Registry Key - Processhighwindows / process_creation
Security Event Logging Disabled via MiniNt Registry Key - Registry Sethighwindows / registry_set

Splunk13

RuleTypeRiskData source
Cisco ASA - Logging Message SuppressionAnomalyNULLCisco ASA Logs
Windows Audit Policy Auditing Option Disabled via AuditpolTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Cleared via AuditpolTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Disabled via AuditpolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Disabled via Legacy AuditpolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Excluded Category via AuditpolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Restored via AuditpolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Audit Policy Security Descriptor Tampering via AuditpolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Disable Windows Event Logging Disable HTTP LoggingAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Global Object Access Audit List Cleared Via AuditpolTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows New Custom Security Descriptor Set On EventLog ChannelAnomalyNULLSysmon EventID 13
Windows New EventLog ChannelAccess Registry Value SetAnomalyNULLSysmon EventID 13
Windows PowerShell Disable HTTP LoggingTTPNULLPowershell Script Block Logging 4104

Groups2

Software1

Campaigns3

Procedure examples6

Groups2

Used byProcedure example
GroupMagic Hound

Magic Hound has executed scripts to disable the event log service.

GroupThreat Group-3390

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.

Software1

Used byProcedure example
ToolWevtutil

Wevtutil can be used to disable specific event logs on the system.

Campaigns3

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems.

CampaignHomeLand Justice

During HomeLand Justice, threat actors deleted Windows events and application logs.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs.

References9

  1. Disable_Win_Event_Logging Open source
    dmcxblue. (n.d.). Disable Windows Event Logging. Retrieved September 10, 2021.
  2. EventLog_Core_Technologies Open source
    Core Technologies. (2021, May 24). Essential Windows Services: EventLog / Windows Event Log. Retrieved September 14, 2021.
  3. Microsoft Adv Security Settings Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  4. Microsoft Audit Policy Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  5. Microsoft auditpol Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  6. T1562.002_redcanaryco Open source
    redcanaryco. (2021, September 3). T1562.002 - Disable Windows Event Logging. Retrieved September 13, 2021.
  7. auditpol.exe_STRONTIC Open source
    STRONTIC. (n.d.). auditpol.exe. Retrieved September 9, 2021.
  8. disable_win_evt_logging Open source
    Heiligenstein, L. (n.d.). REP-25: Disable Windows Event Logging. Retrieved April 7, 2022.
  9. winser19_file_overwrite_bug_twitter Open source
    Naceri, A. (2021, November 7). Windows Server 2019 file overwrite bug. Retrieved April 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.