LoFP LoFP / t1685.005

t1685.005

TitleTags
admin activity
installer tools that disable services, e.g. before log collection agent installation
legitimate deactivation by administrative staff
maintenance activity
rare need to clear logs before doing something. sometimes used by installers or cleaner scripts. the script should be investigated to determine if it's legitimate
rollout of log collection agents (the setup routine often includes a reset of the local eventlog)
scripts and administrative tools used in the monitored environment
system provisioning (system reset before the golden image creation)