Forum Discussion
Anonymous
Jul 22, 2019Clearing audit logs from Domain Controller
Hi there,
Clearing the event logs from the Domain Controller or workstation could be a sign of malicious behavior.
Does Microsoft ATA currently alert on this?
4 Replies
- Mark LewisBrass Contributor
I think this should be triggered from the SIEM. Especially if you're collecting logs from all servers in to the one source. AATP/ATP would only trigger this from a DC, but your SIEM would trigger it from anywhere that is sending the logs.