BIOC
High
✕
EventLog service disabled by a Registry operation
A Registry set-value operation that disables the EventLog service was executed on the machine.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable Windows Event Logging (T1562.002)
Indicator:
Registry registry data = 4 , 3 AND registry key name = HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Services\EventLog AND registry value name = Start AND action type = set_registry_value Host host os = windows
Preventable: yes