Suspicious Attempts to Disable Windows Event Logging Service

Rule Info

Name
Suspicious Attempts to Disable Windows Event Logging Service
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects Suspicious Attempts to Disable Windows Event Logging Service by changing the startup type to "disabled". The Event Logging service records system events in Windows and is critical for security monitoring and auditing. Disabling this service prevents logging of security events, which can indicate malicious activity. Adversaries may use this technique to evade detection and limit data available for security monitoring.
Date
2025-04-09 00:00:00
Modified
None
Id
07cbbee1-6e4e-4319-94d4-68d7b59758e7
Tags
attack.defense-evasion attack.t1562.002 car.2022-03-001
Type
Nextron Sigma feed only (private)

Rule History