Skip to content

S0645 Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.1

Item Value
ID S0645
Associated Names
Version 1.1
Created 14 September 2021
Last Modified 13 October 2022
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1005 Data from Local System Wevtutil can be used to export events from a specific log.12
enterprise T1562 Impair Defenses -
enterprise T1562.002 Disable Windows Event Logging Wevtutil can be used to disable specific event logs on the system.1
enterprise T1070 Indicator Removal -
enterprise T1070.001 Clear Windows Event Logs Wevtutil can be used to clear system and security event logs from the system.13

Groups That Use This Software

ID Name References
G0007 APT28 3