Registry Modification to Disable Event Logging - Registry

Rule Info

Name
Registry Modification to Disable Event Logging - Registry
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects registry modifications attempting to disable the Windows Event Log service. The Event Log service records critical system events in Windows systems. Adversaries may attempt to disable this service to evade detection by preventing the logging of security-relevant events. This technique is commonly used to limit data available for security monitoring and forensic analysis.
Date
2025-04-09 00:00:00
Modified
None
Id
2a965769-0696-4916-9f30-a039b3f80a93
Tags
attack.defense-evasion attack.t1562.002 car.2022-03-001
Type
Nextron Sigma feed only (private)

Rule History