// MITRE ATT&CK

T1685.001 · Disable or Modify Windows Event Log

🎯 Defense Impairment Windows Sub-technique

Sub-technique of T1685 · Disable or Modify Tools.

Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation.(Citation: EventLog_Core_Technologies) This data is used by security tools and analyst...

How to detect & mitigate it

Detecting Disable or Modify Windows Event Log starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.