BIOC Informational

Manipulation of permissions for the Application Event Log

Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:

Registry action type = delete_registry_key , rename_registry_key , set_registry_value , delete_registry_value AND registry key name = *\Services\VSS\Diag Host host os = windows

Preventable: yes