SigmaHQ/windows/builtin/susp_eventlog_cleared.yml
2016-12-27 23:09:41 +01:00

13 lines
475 B
YAML

description: Eventlog Cleared
comment: Some threat groups tend to delete the local 'Security'' Eventlog using certain utitlities
detection:
selection:
- EventLog: Security
EventID:
- 517
- 1102
condition: selection[0]
falsepositives:
- Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
- System provisioning (system reset before the golden image creation)
level: 70