BIOC
Informational
✕
Windows Security audit log was cleared
Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity.
- Module:
- Platform Analytics
- Agent event type:
- Windows event log
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indicator Removal (T1070)
Indicator:
Event Log event log id = 1102 AND event log provider name = Microsoft-Windows-Eventlog Host host os = windows
Preventable: yes