Forum Discussion

Anonymous's avatar
Anonymous
Jul 22, 2019

Clearing audit logs from Domain Controller

Hi there,

 

Clearing the event logs from the Domain Controller or workstation could be a sign of malicious behavior.

Does Microsoft ATA currently alert on this?

 

4 Replies

  • Mark Lewis's avatar
    Mark Lewis
    Brass Contributor

    I think this should be triggered from the SIEM. Especially if you're collecting logs from all servers in to the one source. AATP/ATP would only trigger this from a DC, but your SIEM would trigger it from anywhere that is sending the logs.

    • Anonymous's avatar
      Anonymous

      EliOfek 

      If you consider adding it to ATA. You might add Event 1100 to it as well.

      This event shows up when someone shuts down the event logs.

      • Tali Ash's avatar
        Tali Ash
        Former Employee

        Thanks Deleted , we will look into it, currently are not planning at add such detection.

         

        Thanks,

        Tali

Resources