Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1005 | Data from Local System |
Wevtutil can be used to export events from a specific log.[1][2] |
|
Enterprise | T1562 | .002 | Impair Defenses: Disable Windows Event Logging |
Wevtutil can be used to disable specific event logs on the system.[1] |
Enterprise | T1070 | .001 | Indicator Removal on Host: Clear Windows Event Logs |
Wevtutil can be used to clear system and security event logs from the system.[1][3] |
ID | Name | References |
---|---|---|
G0007 | APT28 |