Wevtutil
MITRE ATT&CK: S0645 View on attack.mitre.org
Aliases: Wevtutil
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:33:20
Context
Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.
Detection coverage
- 44 Sigma rules
Malware & tools used
- Disable or Modify Windows Event Log (attack-pattern)
- Data from Local System (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
Used by threat actors
- Operation Wocao (campaign)
- Volt Typhoon (threat-actor)
- Mustang Panda (threat-actor)
- Aquatic Panda (threat-actor)
- APT28 (threat-actor)
- Play (threat-actor)
- MirrorFace (threat-actor)
Reports & references
- MITRE ATT&CK — S0645 (report)
- Microsoft — Wevtutil (report)