SigmaHQ/rules/windows/builtin/win_susp_eventlog_cleared.yml

16 lines
344 B
YAML
Raw Normal View History

title: Eventlog Cleared
description: One of the Windows Eventlogs has been cleared
reference: https://twitter.com/deviouspolack/status/832535435960209408
author: Florian Roth
logsource:
2017-02-19 10:08:23 +00:00
product: windows
service: system
2016-12-27 13:49:54 +00:00
detection:
2016-12-26 01:21:55 +00:00
selection:
EventID: 104
condition: selection
2016-12-24 11:23:47 +00:00
falsepositives:
- Unknown
level: medium