Windows System Eventlog Cleared (Event ID 104)

Alerts when Microsoft-Windows-Eventlog reports Event ID 104 for core event log channels, indicating log clearing.

FreeUnreviewedSigmahighv1
title: Windows System Eventlog Cleared (Event ID 104)
id: 78feca32-739a-4e32-884f-1c1a391f831f
related:
  - id: a62b37e0-45d3-48d9-a517-90c1a1b0186b
    type: derived
  - id: 100ef69e-3327-481c-8e5c-6d80d9507556
    type: derived
status: test
description: This rule flags Windows instances where the Microsoft-Windows-Eventlog provider logs an Event ID 104, indicating that a Windows core event log was cleared. Attackers can use log clearing to disrupt detection and reduce forensic visibility. Telemetry relies on Windows system logging of Microsoft-Windows-Eventlog Event ID 104 and matching the relevant cleared log channels (including Security, System, and common PowerShell/PowerShellCore operational channels).
references:
  - https://twitter.com/deviouspolack/status/832535435960209408
  - https://www.hybrid-analysis.com/sample/027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745?environmentId=100
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/system/microsoft_windows_eventlog/win_system_susp_eventlog_cleared.yml
author: Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-05-17
modified: 2023-11-15
tags:
  - attack.defense-impairment
  - attack.t1685.005
  - car.2016-04-002
logsource:
  product: windows
  service: system
detection:
  selection:
    EventID: 104
    Provider_Name: Microsoft-Windows-Eventlog
    Channel:
      - Microsoft-Windows-PowerShell/Operational
      - Microsoft-Windows-Sysmon/Operational
      - PowerShellCore/Operational
      - Security
      - System
      - Windows PowerShell
  condition: selection
falsepositives:
  - Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
  - System provisioning (system reset before the golden image creation)
level: high
license: DRL-1.1

What it detects

This rule flags Windows instances where the Microsoft-Windows-Eventlog provider logs an Event ID 104, indicating that a Windows core event log was cleared. Attackers can use log clearing to disrupt detection and reduce forensic visibility. Telemetry relies on Windows system logging of Microsoft-Windows-Eventlog Event ID 104 and matching the relevant cleared log channels (including Security, System, and common PowerShell/PowerShellCore operational channels).

Known false positives

  • Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
  • System provisioning (system reset before the golden image creation)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.