Rule Info
Name
EventLog Metadata Inspection Via Wevtutil
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the eventlog metadata inspection attempt via wevtutil.exe.
Threat actors use these to verify whether security logging is active and gauge
how much time they have before entries are overwritten, before performing intrusive actions.
Date
2026-08-27 00:00:00
Modified
None
Id
a1d2e0f9-b3c4-4d5e-1f6a-7b8c9d0e1f2a
Tags
attack.discovery attack.t1518.001 attack.t1082
Type
Nextron Sigma feed only (private)
