title: Security Eventlog Cleared description: Some threat groups tend to delete the local 'Security' Eventlog using certain utitlities author: Florian Roth logsource: product: windows service: security detection: selection: EventID: - 517 - 1102 condition: selection falsepositives: - Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog) - System provisioning (system reset before the golden image creation) level: high