Logging and monitoring

Event Viewer Security Log Was Cleared

Platform(s)
  • N/A

Compliance Frameworks

Description

The Event Viewer has been cleared on the system. This may indicate an attempt to cover up activity or remove evidence of unauthorized access or malicious activity.
  • Recommended Mitigation

    Investigate the reason why the Event Viewer was cleared and determine if any unauthorized activity occurred on the system.