LoFP LoFP / t1070.001

t1070.001

TitleTags
admin activity
installer tools that disable services, e.g. before log collection agent installation
it is possible that these logs may be legitimately cleared by administrators. filter as needed.
it is possible the event logging service gets shut down due to system errors or legitimately administration tasks. filter as needed.
legitimate deactivation by administrative staff
maintenance activity
network operator may disable audit event logs for debugging purposes.
rare need to clear logs before doing something. sometimes used by installers or cleaner scripts. the script should be investigated to determine if it's legitimate
rollout of log collection agents (the setup routine often includes a reset of the local eventlog)
scripts and administrative tools used in the monitored environment
system provisioning (system reset before the golden image creation)
the wevtutil.exe application is a legitimate windows event log utility. administrators may use it to manage windows event logs.