Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
- Product
- windows
- Service
- security
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-01-10
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows log activity where the Security log is cleared or the Eventlog service records that event logs were cleared, based on Event ID 517 from Provider "Security" or Event ID 1102 from Provider "Microsoft-Windows-Eventlog". Clearing or impairing logs can help an attacker reduce forensic visibility after suspicious activity. The detection relies on Windows Security and Eventlog telemetry capturing these specific event records, including the EventID and Provider_Name fields.
Reporting behind it
- twitter.comhttps://twitter.com/deviouspolack/status/832535435960209408
- hybrid-analysis.comhttps://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100
- github.comhttps://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_audit_log_cleared.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Security and Eventlog Cleared via Event IDs 517 or 1102
id: 3f4db2d8-df65-4046-8e7e-f4587d2c51c8
related:
- id: f2f01843-e7b8-4f95-a35a-d23584476423
type: obsolete
- id: a122ac13-daf8-4175-83a2-72c387be339d
type: obsolete
- id: d99b79d2-0a6f-4f46-ad8b-260b6e17f982
type: derived
status: test
description: This rule identifies Windows log activity where the Security log is cleared or the Eventlog service records that event logs were cleared, based on Event ID 517 from Provider "Security" or Event ID 1102 from Provider "Microsoft-Windows-Eventlog". Clearing or impairing logs can help an attacker reduce forensic visibility after suspicious activity. The detection relies on Windows Security and Eventlog telemetry capturing these specific event records, including the EventID and Provider_Name fields.
references:
- https://twitter.com/deviouspolack/status/832535435960209408
- https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/SecurityEventLogCleared.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_audit_log_cleared.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-01-10
modified: 2022-02-24
tags:
- attack.defense-impairment
- attack.t1685.005
- car.2016-04-002
logsource:
product: windows
service: security
detection:
selection_517:
EventID: 517
Provider_Name: Security
selection_1102:
EventID: 1102
Provider_Name: Microsoft-Windows-Eventlog
condition: 1 of selection_*
falsepositives:
- Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
- System provisioning (system reset before the golden image creation)
level: high
license: DRL-1.1