Attack Ent T1685 001 Disable Or Modify Windows Event Log

Analyze MITRE ATT&CK T1685.001 Disable or Modify Windows Event Log in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685.001, Disable or Modify Windows Event Log, or enterprise ATT&CK. Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits.

santosomar Updated

File contents

santosomar/mitre-attack-agent-skills/tree/main/enterprise/attack-ent-t1685-001-disable-or-modify-windows-event-log commit b2a6d00663

Frequently asked questions

npx skillmds@latest add santosomar/attack-ent-t1685-001-disable-or-modify-windows-event-log