You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Attackers may attempt to clear the Windows Security Event Log in an effort to hide records of their activity during an intrusion. This rule detects that action.
Additional Details
Detail
Value
Type
Match
Category
Defense Evasion
Apply Risk to Entities
device_hostname, device_ip, user_username
Signal Name
The Audit Log was Cleared - 1102
Summary Expression
Windows Event Log cleared on host: {{device_hostname}}