Esc
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.
Disable or Modify Windows Event Log - T1685.001
(Enterprise Technique)
Definition
Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation. This data is used by security tools and analysts to generate detections.
D3FEND Inferred Relationships
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.