Skip to content

[Rule Tuning] Clearing Windows Event Logs #392

Closed
@Samirbous

Description

@Samirbous

Description

Tuning of this rule by adding pe.original_file_name and also adding wevtutil arg /e:false that can be used to disable tracing (e.g. LockerGoga ransomware disables WMI ETW using this command). Example of KQL:

image

Example Data

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions