Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Windows event logs were cleared with PowerShell Informational 3 variations

    Windows event logs were cleared or deleted with PowerShell.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Impairment (TA0112)
    ATT&CK techniques: Disable or Modify Tools: Clear Windows Event Logs (T1685.005)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Attackers may clear events from Windows event logs to remove traces of their malicious activity.
    Investigative actions: Validate if the script that was executed is from a legitimate IT activity. Look for additional suspicious actions that were executed on the host.

    Variations

    Suspicious clear or delete security provider event logs with PowerShell

    High overridden

    Windows event logs were cleared or deleted with PowerShell. overridden

    Suspicious clear or delete default providers event logs with PowerShell

    Medium overridden

    Windows event logs were cleared or deleted with PowerShell. overridden

    Windows event logs were cleared with uncommon PowerShell command line

    Low overridden

    Windows event logs were cleared or deleted with PowerShell. overridden