Wevtutil is the built-in Windows Event Utility that can be abused by adversaries for defense evasion and collection. The provided content states it can be used to clear Windows event logs, specifically System and Security logs, and to disable Windows Event Logging. It can also be used to export events from a specific log and collect data from the local system. In the ATT&CK-style mappings provided, Wevtutil is associated with Data from Local System, Impair Defenses: Disable Windows Event Logging, and Indicator Removal: Clear Windows Event Logs. The content further notes widespread operational abuse of wevtutil by multiple threat actors and malware families to remove forensic evidence, including commands such as "wevtutil cl System" and "wevtutil cl Security." Examples explicitly mentioned include APT28, APT41, BlackCat, HermeticWizard, Meteor, NotPetya, Olympic Destroyer, Operation Wocao, LockBit 2.0, ShrinkLocker, and Volt Typhoon. High-confidence indicators and artifacts directly referenced in the content include command-line usage such as "wevtutil cl System", "wevtutil cl Security", "wevtutil cl system", and "/Q /c wevtutil cl system" or "/Q /c wevtutil cl security".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Aquatic Panda captured local Windows security event log data using wevtutil; Volt Typhoon used Wevtutil to extract event log information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wevtutil is a Windows utility used to query, disable, and clear event logs, often for defense evasion and indicator removal.
Legitimate Windows utility commonly abused to clear event logs (system/security/application) for anti-forensics.
Legitimate Windows utility abused to export Windows Event Logs (data collection).
Built-in Windows command-line utility for managing event logs; can be abused to clear logs for defense evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.