- Download the Clear_Event_Viewer_Logs.bat utility from https://www.tenforums.com.
- Unblock the .bat file. 3. Right-click or press and hold on the .bat file and click/tap on Run as administrator. 4. If prompted by UAC, click/tap on Yes.
- A command prompt will now open to clear the event logs. The command prompt will automatically close when finished.
If the system is exploited with Metasploit, the attacker uses a Meterpreter shell to wipe out all the logs from a Windows system:
- Launch the meterpretershell prompt from the Metasploit Framework.
- Type
clearev
command in the Meterpreter shell prompt and press Enter. The logs of the target system will start being wiped out.
Using the Clear-EventLog
command, the attacker can clear all the PowerShell event logs from local or remote computers:
- Launch Windows PowerShell with administrator privileges.
- Use the following command to clear the entries from the PowerShell event log on the local or remote system:
Clear-EventLog "Windows PowerShell"
- Use the following command to clear specific multiple log types from local or remote systems:
Clear-EventLog-LogName ODiag, OSession -ComputerName localhost, Server02
(This command clears all the log entries in Microsoft Office Diagnostics (ODiag) and Microsoft Office Sessions (OSession) on the local computer and Server02 remote computer.)
- Use the following command to clear all the logs on the specified systems, and then display the event log list:
Clear-EventLog -LogName application, system -confirm
Note: The parameters used in theClear-EventLog
command are as follows: o-ComputerName
: Specifies a remote computer; the default is the local computer o-Confirm
: Prompts you for confirmation before running cmdlet o-LogName
: Specifies the event logs o -WhatIf: Shows what will happen if the cmdlet runs
- Launch command prompt with administrator privileges.
- Use the following command to display a list of event logs: >
wevtutil el
- Use the following command to clear the event logs: >
wevtutil cl
<log_name>log_name
: name of the log to clear, ex: system, application, security. As shown in the screenshot, the attacker can view the list of event logs using the wevtutil utility and clear the system, application, and security event logs.
- Navigate to Start -> Control Panel -> System and Security -> Administrative Tools -> double-click Event Viewer
- Delete the all the log entries logged while compromising the system
- Navigate to the
/var/log
directory on the Linux system - Open the plaintext file containing log messages with text editor
/var/log/messages
- Delete all the log entries logged while compromising the system