Disable or Modify Windows Event Log
Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation.(Citation: EventLog_Core_Technologies) This data is used by security tools and analysts to generate detections. The EventLog service maintains event logs from various system components and applications. By default, the service automatically starts when a system powers on. An audit po...
BY SOURCE
PROCEDURES (17)
Auto-extracted: 3 detections for driver
Auto-extracted: 3 detections for service
Auto-extracted: 3 detections for process creation monitoring
Auto-extracted: 2 detections for registry
Auto-extracted: 2 detections for general monitoring
Auto-extracted: 2 detections for tamper
Auto-extracted: 1 detections for authentication monitoring
Auto-extracted: 1 detections for driver
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for event log
Auto-extracted: 1 detections for http
Auto-extracted: 1 detections for tamper
Auto-extracted: 1 detections for http
Auto-extracted: 1 detections for tamper
Auto-extracted: 1 detections for process access monitoring