Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1685 ✕
Download CSV Show ATT&CK heatmapWindows event logs were cleared with PowerShell Informational 3 variations
Windows event logs were cleared or deleted with PowerShell.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Impairment (TA0112)ATT&CK techniques: Disable or Modify Tools: Clear Windows Event Logs (T1685.005)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers may clear events from Windows event logs to remove traces of their malicious activity.Investigative actions: Validate if the script that was executed is from a legitimate IT activity. Look for additional suspicious actions that were executed on the host.Variations
Suspicious clear or delete security provider event logs with PowerShell
High overridden
Windows event logs were cleared or deleted with PowerShell. overridden
Suspicious clear or delete default providers event logs with PowerShell
Medium overridden
Windows event logs were cleared or deleted with PowerShell. overridden
Windows event logs were cleared with uncommon PowerShell command line
Low overridden
Windows event logs were cleared or deleted with PowerShell. overridden