Best Detection of 2026 Series: Windows Event Log Clearing Post-Compromise

Detects the clearing of Windows Event Logs via wevtutil, PowerShell, or registry modification, occurring within one hour of a remote interactive or network logon event on the same host. This pattern is indicative of anti-forensic activity often performed following lateral movement or prior to destructive actions like ransomware deployment.