Security Eventlog Cleared

 Original Source: [Sigma source]
Title: Security Eventlog Cleared
Status: test
Description:One of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution
References:
  -https://twitter.com/deviouspolack/status/832535435960209408
  -https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100
  -https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml
Author: Florian Roth (Nextron Systems)
Date: 2017-01-10
modified:2022-02-24
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685.005'
  • -'car.2016-04-002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection_517:
    EventID: '517'
    Provider_Name: 'Security'
  selection_1102:
    EventID: '1102'
    Provider_Name: 'Microsoft-Windows-Eventlog'
  condition:1 of selection_*
Falsepositives:
  -Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
  -System provisioning (system reset before the golden image creation)
Level: high