Analytics BIOC Informational

Windows event logs were cleared with PowerShell

Windows event logs were cleared or deleted with PowerShell.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal: Clear Windows Event Logs (T1070.001)
Attacker's goals:

Attackers may clear events from Windows event logs to remove traces of their malicious activity.

Investigative actions:

Validate if the script that was executed is from a legitimate IT activity. Look for additional suspicious actions that were executed on the host.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Suspicious clear or delete security provider event logs with PowerShell High (parent: Informational)
  • Suspicious clear or delete default providers event logs with PowerShell Medium (parent: Informational)
  • Windows event logs were cleared with uncommon PowerShell command line Low (parent: Informational)