Forum Discussion
Anonymous
Jul 22, 2019Clearing audit logs from Domain Controller
Hi there, Clearing the event logs from the Domain Controller or workstation could be a sign of malicious behavior. Does Microsoft ATA currently alert on this?
Mark Lewis
Jul 24, 2019Brass Contributor
I think this should be triggered from the SIEM. Especially if you're collecting logs from all servers in to the one source. AATP/ATP would only trigger this from a DC, but your SIEM would trigger it from anywhere that is sending the logs.