Skip to content

S0645 Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.1

Item Value
ID S0645
Associated Names
Type TOOL
Version 1.2
Created 14 September 2021
Last Modified 25 September 2024
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1005 Data from Local System Wevtutil can be used to export events from a specific log.13
enterprise T1562 Impair Defenses -
enterprise T1562.002 Disable Windows Event Logging Wevtutil can be used to disable specific event logs on the system.1
enterprise T1070 Indicator Removal -
enterprise T1070.001 Clear Windows Event Logs Wevtutil can be used to clear system and security event logs from the system.12

Groups That Use This Software

ID Name References
G0007 APT28 2
G0143 Aquatic Panda Aquatic Panda uses Wevtutil to extract Windows security event log data from victim machines.5
G1017 Volt Typhoon 76
G1040 Play 8
G0129 Mustang Panda Mustang Panda has leveraged Wevtutil to gather information about usernames and Windows Security Event logs.9

References