{"id":"T1685.005","name":"Clear Windows Event Logs","url":"https://attack.mitre.org/techniques/T1685/005","tactics":["defense-impairment"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0532","stix_id":"x-mitre-detection-strategy--d340864e-5685-48d5-8a78-3c55a7169207","name":"Detection of Event Log Clearing on Windows via Behavioral Chain","url":"https://attack.mitre.org/detectionstrategies/DET0532","analytics":[{"id":"AN1472","stix_id":"x-mitre-analytic--6482fa33-322b-47e4-a9f7-c2bcc92d132a","name":"Analytic 1472","description":"Detects behavioral sequence where an adversary gains elevated privileges and clears event logs using native binaries (e.g., wevtutil), PowerShell, or direct file deletion of .evtx files.","url":"https://attack.mitre.org/detectionstrategies/DET0532#AN1472","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=1102","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=23","data_component":"DC0040","data_component_name":"File Deletion","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time range between log-clearing command and 1102 event; tunable to reduce false positives"},{"field":"UserContext","description":"Filter by admin/elevated users; allow tuning to detect abuse of high-privilege accounts"},{"field":"CommandLinePattern","description":"Match common variations of log-clearing commands like `Remove-EventLog`, `wevtutil cl`"},{"field":"TargetLogName","description":"Scope detection to Security, System, Application, or custom logs based on environment"}],"live":true,"detection_strategies":["DET0532"],"techniques":["T1685.005"]}],"live":true,"version":"1.0","techniques":["T1685.005"]}],"sigma_rules":[{"id":"0f017df3-8f5a-414f-ad6b-24aff1128278","title":"Suspicious Eventlog Clear","author":"Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"medium","date":"2022-09-12","modified":"2025-10-06","description":"Detects usage of known powershell cmdlets such as \"Clear-EventLog\" to clear the Windows event logs","references":["https://twitter.com/oroneequalsone/status/1568432028361830402","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.001/T1070.001.md","https://eqllib.readthedocs.io/en/latest/analytics/5b223758-07d6-4100-9e11-238cfdd0fe97.html","https://stackoverflow.com/questions/66011412/how-to-clear-a-event-log-in-powershell-7","https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.eventing.reader.eventlogsession.clearlog?view=windowsdesktop-9.0&viewFallbackFrom=dotnet-plat-ext-5.0#System_Diagnostics_Eventing_Reader_EventLogSession_ClearLog_System_String_","https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.eventlog.clear"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685.005"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_clear_eventlog.yml","techniques":["T1685.005"],"cves":[]},{"id":"100ef69e-3327-481c-8e5c-6d80d9507556","title":"Important Windows Eventlog Cleared","author":"Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-05-17","modified":"2023-11-15","description":"Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by \"wevtutil cl\" command execution","references":["https://twitter.com/deviouspolack/status/832535435960209408","https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100"],"logsource":{"product":"windows","service":"system"},"tags":["attack.defense-impairment","attack.t1685.005","car.2016-04-002"],"path":"rules/windows/builtin/system/microsoft_windows_eventlog/win_system_susp_eventlog_cleared.yml","techniques":["T1685.005"],"cves":[]},{"id":"79aeeb41-8156-4fac-a0cd-076495ab82a1","title":"NotPetya Ransomware Activity","author":"Florian Roth (Nextron Systems), Tom Ueltschi","status":"test","level":"critical","date":"2019-01-16","modified":"2022-12-15","description":"Detects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil","references":["https://securelist.com/schroedingers-petya/78870/","https://www.hybrid-analysis.com/sample/64b0b58a2c030c77fdb2b537b2fcc4af432bc55ffb36599a31d418c7c69e94b1?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1218.011","attack.t1685.005","attack.credential-access","attack.t1003.001","car.2016-04-002","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/NotPetya/proc_creation_win_malware_notpetya.yml","techniques":["T1218.011","T1685.005","T1003.001"],"cves":[]},{"id":"a62b37e0-45d3-48d9-a517-90c1a1b0186b","title":"Eventlog Cleared","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-01-10","modified":"2023-11-15","description":"One of the Windows Eventlogs has been cleared. e.g. caused by \"wevtutil cl\" command execution","references":["https://twitter.com/deviouspolack/status/832535435960209408","https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100"],"logsource":{"product":"windows","service":"system"},"tags":["attack.defense-impairment","attack.t1685.005","car.2016-04-002"],"path":"rules/windows/builtin/system/microsoft_windows_eventlog/win_system_eventlog_cleared.yml","techniques":["T1685.005"],"cves":[]},{"id":"cc36992a-4671-4f21-a91d-6c2b72a2edf5","title":"Suspicious Eventlog Clearing or Configuration Change Activity","author":"Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"stable","level":"high","date":"2019-09-26","modified":"2026-06-01","description":"Detects the clearing or configuration tampering of EventLog using utilities such as \"wevtutil\", \"powershell\" and \"wmic\".\nThis technique were seen used by threat actors and ransomware strains in order to evade defenses.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.001/T1070.001.md","https://eqllib.readthedocs.io/en/latest/analytics/5b223758-07d6-4100-9e11-238cfdd0fe97.html","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil","https://gist.github.com/fovtran/ac0624983c7722e80a8f5a4babb170ee","https://jdhnet.wordpress.com/2017/12/19/changing-the-location-of-the-windows-event-logs/","https://www.linkedin.com/posts/huntress-labs_when-a-sketchy-incident-hits-your-network-activity-7304940371078238208-Th_l/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAJTlRcB28IaUtg03HUU-IdliwzoAL1flGc","https://stackoverflow.com/questions/66011412/how-to-clear-a-event-log-in-powershell-7","https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.eventing.reader.eventlogsession.clearlog?view=windowsdesktop-9.0&viewFallbackFrom=dotnet-plat-ext-5.0#System_Diagnostics_Eventing_Reader_EventLogSession_ClearLog_System_String_","https://learn.microsoft.com/en-us/dotnet/api/system.diagnostics.eventlog.clear"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685.005","attack.t1685.001","car.2016-04-002"],"path":"rules/windows/process_creation/proc_creation_win_susp_eventlog_clear.yml","techniques":["T1685.005","T1685.001"],"cves":[]},{"id":"cd1f961e-0b96-436b-b7c6-38da4583ec00","title":"Suspicious Windows Trace ETW Session Tamper Via Logman.EXE","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-02-11","modified":"2023-02-21","description":"Detects the execution of \"logman\" utility in order to disable or delete Windows trace sessions","references":["https://twitter.com/0gtweet/status/1359039665232306183?s=21","https://ss64.com/nt/logman.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","attack.t1685.005"],"path":"rules/windows/process_creation/proc_creation_win_logman_disable_eventlog.yml","techniques":["T1685","T1685.005"],"cves":[]},{"id":"d4f1a2b3-7c8e-4d5f-b6a9-1e0c2d3f4e5b","title":"Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"medium","date":"2026-07-01","modified":null,"description":"Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method.\nEvent 5858 in the WMI-Activity operational log is an error event, meaning it is only generated\nwhen the WMI operation encounters an error (e.g. access denied, provider failure).\nIt could be an indication of an attacker attempting to clear event logs via WMI, but failing due to insufficient privileges or other issues.\nSuccessful clearing operations will NOT produce this event; for those, correlate with\nSecurity event 1102 or System event 104.\n","references":["https://learn.microsoft.com/en-us/windows/win32/cimwin32prov/cleareventlog-method-in-class-win32-nteventlogfile"],"logsource":{"product":"windows","service":"wmi"},"tags":["attack.defense-impairment","attack.t1685.005"],"path":"rules/windows/builtin/wmi/win_wmi_activity_nteventlogfile_cleareventlog.yml","techniques":["T1685.005"],"cves":[]},{"id":"d99b79d2-0a6f-4f46-ad8b-260b6e17f982","title":"Security Eventlog Cleared","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-01-10","modified":"2022-02-24","description":"One of the Windows Eventlogs has been cleared. e.g. caused by \"wevtutil cl\" command execution","references":["https://twitter.com/deviouspolack/status/832535435960209408","https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100","https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685.005","car.2016-04-002"],"path":"rules/windows/builtin/security/win_security_audit_log_cleared.yml","techniques":["T1685.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}