BIOC Informational

Windows Security audit log was cleared

Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity.

Module:
Platform Analytics
Agent event type:
Windows event log
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal (T1070)
Indicator:

Event Log event log id = 1102 AND event log provider name = Microsoft-Windows-Eventlog Host host os = windows

Preventable: yes