logo

Hackers Exploited Windows Event Logs Tool log Manipulation, And Data Exfiltration

ID: 4edb1239-0db6-549d-b449-362a5377c2a6

STIX ID: report--4edb1239-0db6-549d-b449-362a5377c2a6

Feed Name: GBHackers

Date Published: 2024-12-03

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

This report explains how attackers abuse the Windows wevtutil.exe tool as a LOLBAS technique to clear, query, and export event logs, enabling defense evasion and potential data exfiltration. It highlights operational details and artifacts—such as the need for elevated privileges, the generation of Event ID 1102 when clearing the Security log, and lack of native logging for non-Security log clearing—while noting that selective clearing of individual events is not possible. Recommended defenses include enabling relevant audit policies (e.g., “Audit Other Object Access Events”), enforcing strict access controls on event logs, enhancing behavioral monitoring, and flagging suspicious toolchains that combine wevtutil.exe with utilities like makecab.exe and certutil.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.