Analytics BIOC
Informational
✕
Windows event logs were cleared with PowerShell
Windows event logs were cleared or deleted with PowerShell.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal: Clear Windows Event Logs (T1070.001)
Attacker's goals:
Attackers may clear events from Windows event logs to remove traces of their malicious activity.
Investigative actions:
Validate if the script that was executed is from a legitimate IT activity. Look for additional suspicious actions that were executed on the host.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Suspicious clear or delete security provider event logs with PowerShell High (parent: Informational)
- Suspicious clear or delete default providers event logs with PowerShell Medium (parent: Informational)
- Windows event logs were cleared with uncommon PowerShell command line Low (parent: Informational)