Windows - Deletion Event Log Detection Test
Deletion of Windows Event Log SIEM Detection Test
The deletion of a Windows Event Viewer Security log is a common pattern of post-attack evasion by malicious software and attackers. By monitoring for this deletion, you can have immediate awareness of what should be an unusual activity -- with the benefit of having those same deleted event logs stored in Blumira for analysis.How to Test Deletion of Windows Security Log
Prerequisites:- Windows Host must be set up with NxLog configuration and properly logging to Blumira
- GPO Advanced Logging (Logmira) - must be installed and logging properly to Blumira
- There are various ways to delete the Security Event Viewer Logs, however the easiest is to use a PowerShell command
- Open PowerShell with "Run as Administrator"
- Run the command
Clear-EventLog "Security"
- This detection test will trigger a finding in your Blumira console and the appropriate notifications per your Blumira settings
Additional Security Resources
View All Posts
Customer Success Stories
7 min read
| October 10, 2024
Customer Story: Girl Scouts of Southeastern Michigan
Read More
Customer Success Stories
5 min read
| September 25, 2024
Customer Story: Mid-Sized Manufacturing Firm
Read More
Product Updates
6 min read
| July 22, 2024