Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0040 ✕ technique: T1490 ✕
Download CSV Show ATT&CK heatmapWindows Event Log was cleared using wevtutil.exe Low 2 variations
A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Inhibit System Recovery (T1490)Required data: XDR AgentAttacker's goals: Delete logs to cover tracks of the malicious activity, making it harder to perform analysis.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.Variations
Security Event Log was cleared using wevtutil.exe
High overridden
A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. overridden
A Sensitive Windows Event Log was cleared using wevtutil.exe
Medium overridden
A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. overridden