Wevtutil

MITRE ATT&CK: S0645 View on attack.mitre.org

Aliases: Wevtutil

Operating systems
windows
Profile updated
2026-07-07 15:33:20

Context

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.

Detection coverage

  • 44 Sigma rules

Malware & tools used

  • Disable or Modify Windows Event Log (attack-pattern)
  • Data from Local System (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0645 (report)
  • Microsoft — Wevtutil (report)

External references