BIOC High

EventLog service disabled by a Registry operation

A Registry set-value operation that disables the EventLog service was executed on the machine.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable Windows Event Logging (T1562.002)
Indicator:

Registry registry data = 4 , 3 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Services\EventLog AND registry value name = Start AND action type = set_registry_value Host host os = windows

Preventable: yes