Suspicious Use of PsLogList — Detection Rule

Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs

Read the full analysis on IntelFusions