diff --git a/atomics/T1562.002/T1562.002.yaml b/atomics/T1562.002/T1562.002.yaml index 9de651eb..67a10f9e 100644 --- a/atomics/T1562.002/T1562.002.yaml +++ b/atomics/T1562.002/T1562.002.yaml @@ -80,6 +80,7 @@ atomic_tests: name: command_prompt elevation_required: true - name: Disable Event Logging with wevtutil + auto_generated_guid: b26a3340-dad7-4360-9176-706269c74103 description: | Wevtutil can be used to disable logs. NOTE: RansomEXX ransomware uses this to disable Security logs post-encryption. diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 97a83011..3a27e373 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -796,3 +796,4 @@ e03ada14-0980-4107-aff1-7783b2b59bb1 3d111226-d09a-4911-8715-fe11664f960d 1289f78d-22d2-4590-ac76-166737e1811b c943d285-ada3-45ca-b3aa-7cd6500c6a48 +b26a3340-dad7-4360-9176-706269c74103