Account Management Events
Event Log Manipulation Detection: Safeguarding Critical Evidence
Key Event IDs for Event Log Manipulation
1. Event ID 1102: Security Log Cleared
2. Event ID 104: Any Log Cleared
3. Event ID 1100: Event Logging Disabled
Why Attackers Clear or Disable Logs
1. Covering Tracks
2. Disrupting Security Monitoring
3. Avoiding Detection
Mitigations and Considerations
1. Privilege Requirements
2. SIEM Integration
3. Behavioral Analysis
4. Enforce Logging Policies
Example Detection Workflow
Key Points
Last updated