Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. Wevtutil

Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.[1]

ID: S0645
Type: TOOL
Platforms: Windows
Contributors: Viren Chaudhari, Qualys; Harshal Tupsamudre, Qualys
Version: 1.2
Created: 14 September 2021
Last Modified: 25 September 2024
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1005Data from Local System

Wevtutil can be used to export events from a specific log.[1][2]

EnterpriseT1562.002Impair Defenses:Disable Windows Event Logging

Wevtutil can be used to disable specific event logs on the system.[1]

EnterpriseT1070.001Indicator Removal:Clear Windows Event Logs

Wevtutil can be used to clear system and security event logs from the system.[1][3]

Groups That Use This Software

IDNameReferences
G0007APT28

[3]

G0143Aquatic Panda

Aquatic Panda usesWevtutil to extract Windows security event log data from victim machines.[4]

G1017Volt Typhoon

[5][6]

G1040Play

[7]

G0129Mustang Panda

Mustang Panda has leveragedWevtutil to gather information about usernames and Windows Security Event logs.[8]

Campaigns

IDNameDescription
C0014Operation Wocao

DuringOperation Wocao, threat actors usedWevtutil to delete system and security event logs withwevtutil cl system andwevtutil cl security.[9]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp