wevtutil.exe deployment for log evasion( Corrected file extension ) #427
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Wevtutil.exe is created by windows to be used by system administrator's and for mainly trouble shooting purposes; not for actors to abuse to hide their tracks or create visibility gaps. The binary really shines less when used to straight up clear logs, as it is useful to momentarily disable logs of interest to preform certain actions more stealthy and then resume logging as normal.
It is unlikely that defenders would notice a 2-3 minute gap in logging and thus can allow you crucial minutes to preform nosier/high risk activity while reducing risk of detection. Many red teamers and pentesters(at my workplace included) were not aware of the ability to pause logging and resume it with relative ease and expressed interest in having it handy. [Potentially others are in the same spot and would benefit from having it in the project!