Suspicious Eventlog Clearing or Configuration Change Activity — Detection Rule

Detects the clearing or configuration tampering of EventLog using utilities such as "wevtutil", "powershell" and "wmic". This technique were seen used by threat actors and ransomware strains in order to evade defenses.

Read the full analysis on IntelFusions