Sub-technique of T1685 Disable or Modify Tools.View on attack.mitre.org
Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit.
With administrator privileges, the event logs can be cleared with the following utility commands:
* `wevtutil cl system`
* `wevtutil cl application`
* `wevtutil cl security`
These logs may also be cleared through other mechanisms, such as the event viewer GUI or PowerShell. For example, adversaries may use the PowerShell command `Remove-EventLog -LogName Security` to delete the Security EventLog and after reboot, disable future logging. Note: events may still be generated and logged in the .evtx file between the time the command is run and the reboot.
Adversaries may also attempt to clear logs by directly deleting the stored log files within `C:\Windows\System32\winevt\logs\`.
Rules on DetectionCode tagged with T1685.005.
| Rule | Level | Log source |
|---|---|---|
| Important Windows Eventlog Cleared | high | windows / NULL |
| Security Eventlog Cleared | high | windows / NULL |
| Suspicious Eventlog Clearing or Configuration Change Activity | high | windows / process_creation |
| Suspicious Windows Trace ETW Session Tamper Via Logman.EXE | high | windows / process_creation |
| Eventlog Cleared | medium | windows / NULL |
| Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog | medium | windows / NULL |
| Suspicious Eventlog Clear | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Disable Logs Using WevtUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious wevtutil Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Event Log Cleared | TTP | NULL | Windows Event Log Security 1102, Windows Event Log System 104 |
| Windows Event Logging Service Has Shutdown | Hunting | NULL | Windows Event Log Security 1100 |
| Windows Eventlog Cleared Via Wevtutil | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has cleared event logs, including by using the commands |
| GroupAPT32 | APT32 has cleared select event log entries. |
| GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
| GroupAPT41 | APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events. |
| GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
| GroupChimera | Chimera has cleared event logs on compromised hosts. |
| GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| GroupFIN5 | FIN5 has cleared event logs from victims. |
| Used by | Procedure example |
|---|---|
| MalwareApostle | Apostle will attempt to delete all event logs on a victim machine following file wipe activity. |
| MalwareBlackCat | BlackCat can clear Windows event logs using `wevtutil.exe`. |
| MalwareBlackEnergy | The BlackEnergy component KillDisk is capable of deleting Windows Event Logs. |
| MalwareDUSTTRAP | DUSTTRAP can delete infected system log information. |
| MalwareFinFisher | FinFisher clears the system event logs using |
| Malwaregh0st RAT | gh0st RAT is able to wipe event logs. |
| MalwareHermeticWiper | HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system. |
| MalwareHermeticWizard | HermeticWizard has the ability to use `wevtutil cl system` to clear event logs. |
| Used by | Procedure example |
|---|---|
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise. |
| CampaignOperation Wocao | During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.