[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQPWt0jLFLmLzv6E9mtNeV-_3-6Q5cMGTB57_8HXqE60":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1057,"How can I clear all Windows event logs using built-in tools?","You can use `wevtutil.exe`, which is included by default in Windows 7 and later. Running `wevtutil cl {LogName}` (e.g., `wevtutil cl Application`) deletes all entries in that log category. For more advanced clearing options, you can also use tools like NSA DanderSpiritz, which offers commands like `eventlogclear -log Application`. For details on deleting single entries, see [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries).","\u003Cp>You can use `wevtutil.exe`, which is included by default in Windows 7 and later. Running `wevtutil cl {LogName}` (e.g., `wevtutil cl Application`) deletes all entries in that log category. For more advanced clearing options, you can also use tools like NSA DanderSpiritz, which offers commands like `eventlogclear -log Application`. For details on deleting single entries, see [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-deletion-and-bypass-of-windows-logs\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-clear-all-windows-event-logs-using-built-in-tools-1777480831829","wevtutil, Windows event logs, DanderSpiritz, log clearing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},258,"Penetration Techniques - Deletion and Bypass of Windows Logs","penetration-techniques-deletion-and-bypass-of-windows-logs","Learn techniques to clear and bypass Windows logs for penetration testing, including wevtutil, NSA tools, and thread termination methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, Windows logs often record sensitive operations on the system, such as adding users, remote login execution, etc.\u003C\u002Fp>\u003Cp>For a complete penetration test, it is common to choose to clear and bypass Windows logs. For defenders, understanding common bypass methods also helps better protect their systems.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce common methods for clearing and bypassing Windows logs, share experiences, and help everyone.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for clearing Windows logs\u003C\u002Fli>\u003Cli>Two methods for bypassing Windows logs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Windows Logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows logs include five categories:\u003C\u002Fp>\u003Cul>\u003Cli>Application\u003C\u002Fli>\u003Cli>Security\u003C\u002Fli>\u003Cli>Setup\u003C\u002Fli>\u003Cli>System\u003C\u002Fli>\u003Cli>Forward events\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>View method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1、\u003C\u002Fstrong> Via panel\u003C\u002Fp>\u003Cp>Location as follows:\u003C\u002Fp>\u003Cp>Control Panel\\System and Security-View event logs-Windows Logs\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015590927_0_1d82671e3d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2、\u003C\u002Fstrong> Via Powershell\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Cp>View all logs:\u003C\u002Fp>\u003Cp>Get-WinEvent\u003C\u002Fp>\u003Cp>View logs under the Application category:\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Application\";}\u003C\u002Fp>\u003Ch2>0x03 Common methods for clearing Windows logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. wevtutil.exe\u003C\u002Fh3>\u003Cp>Included by default in the operating system, supported systems: Windows 7 and above\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>  List log statistics, query all log information, including time and count\u003C\u002Fp>\u003Cp>wevtutil.exe gli Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015596152_1_48382c1f5c.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>View log content for specified category\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015598430_2_527193b056.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Delete all content of this log category\u003C\u002Fp>\u003Cp>wevtutil cl Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015600693_3_4a60916ba4.jpeg\">\u003C\u002Fp>\u003Cp>All Application logs cleared, count is 0\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Delete single entry\u003C\u002Fp>\u003Cp>Not yet supported\u003C\u002Fp>\u003Ch3>2. NSA DanderSpiritz\u003C\u002Fh3>\u003Cp>DanderSpritz is a GUI-based remote control tool from NSA\u003C\u002Fp>\u003Cp>For related information, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FNSA-DanderSpiritz-Testing-Guide---Trojan-Generation-and-Testing\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> List log statistics, query all log information, including time and count\u003C\u002Fp>\u003Cp>eventlogquery -log Application\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong> View log content of a specified category\u003C\u002Fp>\u003Cp>eventlogfilter -log Application -num 10\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong> Delete all content of that log category\u003C\u002Fp>\u003Cp>eventlogclear -log Application\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong> Delete a single entry\u003C\u002Fp>\u003Cp>eventlogedit -log Application -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Ch2>0x04 Bypass Methods for Windows Event Log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The ideas introduced in this article are referenced from Halil Dalabasmaz@hlldz's article, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fartofpwn.com\u002Fphant0m-killing-windows-event-log.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Bypass Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Event Log corresponds to the eventlog service. Locate the svchost.exe process associated with this service, then filter out the specific threads within the svchost.exe process that implement the logging functionality. Call TerminateThread to end these threads, thereby disrupting the logging capability.\u003C\u002Fp>\u003Cp>\u003Cstrong>Special Aspect:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since only the threads responsible for logging are terminated, the Windows Event Log service itself remains intact and its status continues to show as running.\u003C\u002Fp>\u003Ch3>Bypass Method One\u003C\u002Fh3>\u003Cp>\u003Cstrong>1、\u003C\u002Fstrong>Locate the PID of the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>\u003Cstrong>2、\u003C\u002Fstrong>Enumerate all threads within that process\u003C\u002Fp>\u003Cp>\u003Cstrong>3、\u003C\u002Fstrong> Determine if the thread meets the conditions\u003C\u002Fp>\u003Cp>The Windows Event Log service needs to call wevtsvc.dll, with the full path being %WinDir%\\System32\\wevtsvc.dll\u003C\u002Fp>\u003Cp>Moreover, if the thread calls wevtsvc.dll, it can be determined that the thread implements the logging function\u003C\u002Fp>\u003Cp>\u003Cstrong>4、\u003C\u002Fstrong> Terminate the thread\u003C\u002Fp>\u003Cp>Use TerminateThread\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Halil Dalabasmaz@hlldz implemented method one using PowerShell, and the complete code can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhlldz\u002FInvoke-Phant0m\u003C\u002Fp>\u003Cp>After executing the PowerShell script, the Windows logging function fails and cannot record logs, as shown in the operation below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015603538_4_1aaf8be7d7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>5、\u003C\u002Fstrong> Recovery method\u003C\u002Fp>\u003Cp>Terminate the process svchost.exe\u003C\u002Fp>\u003Cp>Restart the Windows Event Log service:\u003C\u002Fp>\u003Cp>net start eventlog\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015606163_5_bebf150427.jpeg\">\u003C\u002Fp>\u003Ch3>Bypass method two\u003C\u002Fh3>\u003Cp>\u003Cstrong>1.\u003C\u002Fstrong> Locate the pid of the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>PowerShell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Class win32_service -Filter \"name = 'eventlog'\" | select -exp ProcessId\u003C\u002Fp>\u003Cp>Found the pid of svchost.exe is 7008, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015607647_6_658053c73d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2.\u003C\u002Fstrong> Traverse all threads in this process\u003C\u002Fp>\u003Cp>Using PsList\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb896682.aspx\u003C\u002Fp>\u003Cp>The specific parameters are as follows:\u003C\u002Fp>\u003Cp>pslist.exe \u002Faccepteula -d 7008\u003C\u002Fp>\u003Cp>Retrieve all threads within the process svchost.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015609108_7_bbf8eaf827.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3.\u003C\u002Fstrong>Determine whether the thread meets the condition\u003C\u002Fp>\u003Cp>Obtain the service corresponding to the thread; if it is eventlog, the condition is met\u003C\u002Fp>\u003Cp>Tool used: ScTagQuery\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.winsiderss.com\u002Ftools\u002Fsctagquery\u002Fsctagqry.zip\u003C\u002Fp>\u003Cp>The specific parameters are as follows:\u003C\u002Fp>\u003Cp>sctagqry.exe -t 7928\u003C\u002Fp>\u003Cp>Determine the service corresponding to the thread based on the returned Service Tag result\u003C\u002Fp>\u003Cp>Locate the thread corresponding to eventlog, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015611277_8_16ff5dbea8.jpeg\">\u003C\u002Fp>\u003Cp>Thread 8136 meets the criteria, try sequentially until all eligible threads are obtained\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Process Explorer can simplify this process\u003C\u002Fp>\u003Cp>Find the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015613037_9_010ae56ac9.jpeg\">\u003C\u002Fp>\u003Cp>Right-click to view properties, select the Threads tab, view threads, and directly obtain the service corresponding to the thread\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015614269_10_ebad27df76.jpeg\">\u003C\u002Fp>\u003Cp>The eligible thread TIDs are:\u003C\u002Fp>\u003Cul>\u003Cli>8136\u003C\u002Fli>\u003Cli>8052\u003C\u002Fli>\u003Cli>6708\u003C\u002Fli>\u003Cli>2316\u003C\u002Fli>\u003Cli>6356\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>4、\u003C\u002Fstrong>End Thread\u003C\u002Fp>\u003Cp>Call TerminateThread\u003C\u002Fp>\u003Cp>Implemented in C++, partial code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>int main(int argc, char* argv[])\u003Cbr>{\t\u003Cbr>\tprintf(\"TerminateThread TID:\\n\");   \t\u003Cbr>\tfor(int i=1;i\u003Cargc;i++)\u003Cbr>\t{\t\u003Cbr>\t\tprintf(\"%s\\n\",argv[i]);\u003Cbr>\t\tHANDLE hThread = OpenThread(0x0001, FALSE,atoi(argv[i]));\u003Cbr>\t\tif(TerminateThread(hThread,0)==0)\u003Cbr>\t\t\tprintf(\"[!] TerminateThread Error, TID: %s \\n\",argv[i]);\u003Cbr>\t\tCloseHandle(hThread);\u003Cbr>\t}  \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fargc;i++)\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The console supports passing multiple parameters. Pass 5 TIDs to it: 8136 8052 6708 2316 6356\u003C\u002Fp>\u003Cp>Automatically terminates the corresponding threads, logging function becomes ineffective\u003C\u002Fp>\u003Cp>Specific operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015615284_11_c8420b619e.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Later I will update the complete implementation code for this bypass method on GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Installing Sysmon can extend Windows logging functionality\u003C\u002Fh3>\u003Cp>For related introduction and bypass techniques, refer to;\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E9%80%9A%E8%BF%87APC%E5%AE%9E%E7%8E%B0Dll%E6%B3%A8%E5%85%A5-%E7%BB%95%E8%BF%87Sysmon%E7%9B%91%E6%8E%A7\u003C\u002Fp>\u003Ch3>2. Bypass methods only target Windows Event Logs\u003C\u002Fh3>\u003Cp>Ineffective against Application and Service Logs, such as Windows PowerShell\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616436_12_4f90be3620.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for clearing and bypassing Windows Event Logs, hoping to assist everyone. Next, we will share the specific program implementation for bypass method two.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, Windows logs often record sensitive operations on the system, such as adding users, remote login execution, etc.\u003C\u002Fp>\u003Cp>For a complete penetration test, it is common to choose to clear and bypass Windows logs. For defenders, understanding common bypass methods also helps better protect their systems.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce common methods for clearing and bypassing Windows logs, share experiences, and help everyone.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for clearing Windows logs\u003C\u002Fli>\u003Cli>Two methods for bypassing Windows logs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Windows Logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Windows logs include five categories:\u003C\u002Fp>\u003Cul>\u003Cli>Application\u003C\u002Fli>\u003Cli>Security\u003C\u002Fli>\u003Cli>Setup\u003C\u002Fli>\u003Cli>System\u003C\u002Fli>\u003Cli>Forward events\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>View method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1、\u003C\u002Fstrong> Via panel\u003C\u002Fp>\u003Cp>Location as follows:\u003C\u002Fp>\u003Cp>Control Panel\\System and Security-View event logs-Windows Logs\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015590927_0_1d82671e3d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2、\u003C\u002Fstrong> Via Powershell\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Cp>View all logs:\u003C\u002Fp>\u003Cp>Get-WinEvent\u003C\u002Fp>\u003Cp>View logs under the Application category:\u003C\u002Fp>\u003Cp>Get-WinEvent -FilterHashtable @{logname=\"Application\";}\u003C\u002Fp>\u003Ch2>0x03 Common methods for clearing Windows logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. wevtutil.exe\u003C\u002Fh3>\u003Cp>Included by default in the operating system, supported systems: Windows 7 and above\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>  List log statistics, query all log information, including time and count\u003C\u002Fp>\u003Cp>wevtutil.exe gli Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015596152_1_48382c1f5c-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>View log content for specified category\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015598430_2_527193b056-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Delete all content of this log category\u003C\u002Fp>\u003Cp>wevtutil cl Application\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015600693_3_4a60916ba4-1.jpeg\">\u003C\u002Fp>\u003Cp>All Application logs cleared, count is 0\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Delete single entry\u003C\u002Fp>\u003Cp>Not yet supported\u003C\u002Fp>\u003Ch3>2. NSA DanderSpiritz\u003C\u002Fh3>\u003Cp>DanderSpritz is a GUI-based remote control tool from NSA\u003C\u002Fp>\u003Cp>For related information, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002FNSA-DanderSpiritz-Testing-Guide---Trojan-Generation-and-Testing\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> List log statistics, query all log information, including time and count\u003C\u002Fp>\u003Cp>eventlogquery -log Application\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong> View log content of a specified category\u003C\u002Fp>\u003Cp>eventlogfilter -log Application -num 10\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong> Delete all content of that log category\u003C\u002Fp>\u003Cp>eventlogclear -log Application\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong> Delete a single entry\u003C\u002Fp>\u003Cp>eventlogedit -log Application -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Ch2>0x04 Bypass Methods for Windows Event Log\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The ideas introduced in this article are referenced from Halil Dalabasmaz@hlldz's article, with the address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fartofpwn.com\u002Fphant0m-killing-windows-event-log.html\u003C\u002Fp>\u003Cp>\u003Cstrong>Bypass Principle:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Event Log corresponds to the eventlog service. Locate the svchost.exe process associated with this service, then filter out the specific threads within the svchost.exe process that implement the logging functionality. Call TerminateThread to end these threads, thereby disrupting the logging capability.\u003C\u002Fp>\u003Cp>\u003Cstrong>Special Aspect:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since only the threads responsible for logging are terminated, the Windows Event Log service itself remains intact and its status continues to show as running.\u003C\u002Fp>\u003Ch3>Bypass Method One\u003C\u002Fh3>\u003Cp>\u003Cstrong>1、\u003C\u002Fstrong>Locate the PID of the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>\u003Cstrong>2、\u003C\u002Fstrong>Enumerate all threads within that process\u003C\u002Fp>\u003Cp>\u003Cstrong>3、\u003C\u002Fstrong> Determine if the thread meets the conditions\u003C\u002Fp>\u003Cp>The Windows Event Log service needs to call wevtsvc.dll, with the full path being %WinDir%\\System32\\wevtsvc.dll\u003C\u002Fp>\u003Cp>Moreover, if the thread calls wevtsvc.dll, it can be determined that the thread implements the logging function\u003C\u002Fp>\u003Cp>\u003Cstrong>4、\u003C\u002Fstrong> Terminate the thread\u003C\u002Fp>\u003Cp>Use TerminateThread\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Halil Dalabasmaz@hlldz implemented method one using PowerShell, and the complete code can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhlldz\u002FInvoke-Phant0m\u003C\u002Fp>\u003Cp>After executing the PowerShell script, the Windows logging function fails and cannot record logs, as shown in the operation below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015603538_4_1aaf8be7d7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>5、\u003C\u002Fstrong> Recovery method\u003C\u002Fp>\u003Cp>Terminate the process svchost.exe\u003C\u002Fp>\u003Cp>Restart the Windows Event Log service:\u003C\u002Fp>\u003Cp>net start eventlog\u003C\u002Fp>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015606163_5_bebf150427-1.jpeg\">\u003C\u002Fp>\u003Ch3>Bypass method two\u003C\u002Fh3>\u003Cp>\u003Cstrong>1.\u003C\u002Fstrong> Locate the pid of the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>PowerShell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Class win32_service -Filter \"name = 'eventlog'\" | select -exp ProcessId\u003C\u002Fp>\u003Cp>Found the pid of svchost.exe is 7008, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015607647_6_658053c73d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2.\u003C\u002Fstrong> Traverse all threads in this process\u003C\u002Fp>\u003Cp>Using PsList\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fbb896682.aspx\u003C\u002Fp>\u003Cp>The specific parameters are as follows:\u003C\u002Fp>\u003Cp>pslist.exe \u002Faccepteula -d 7008\u003C\u002Fp>\u003Cp>Retrieve all threads within the process svchost.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015609108_7_bbf8eaf827-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3.\u003C\u002Fstrong>Determine whether the thread meets the condition\u003C\u002Fp>\u003Cp>Obtain the service corresponding to the thread; if it is eventlog, the condition is met\u003C\u002Fp>\u003Cp>Tool used: ScTagQuery\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.winsiderss.com\u002Ftools\u002Fsctagquery\u002Fsctagqry.zip\u003C\u002Fp>\u003Cp>The specific parameters are as follows:\u003C\u002Fp>\u003Cp>sctagqry.exe -t 7928\u003C\u002Fp>\u003Cp>Determine the service corresponding to the thread based on the returned Service Tag result\u003C\u002Fp>\u003Cp>Locate the thread corresponding to eventlog, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015611277_8_16ff5dbea8-1.jpeg\">\u003C\u002Fp>\u003Cp>Thread 8136 meets the criteria, try sequentially until all eligible threads are obtained\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Process Explorer can simplify this process\u003C\u002Fp>\u003Cp>Find the svchost.exe process corresponding to the eventlog service\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015613037_9_010ae56ac9-1.jpeg\">\u003C\u002Fp>\u003Cp>Right-click to view properties, select the Threads tab, view threads, and directly obtain the service corresponding to the thread\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015614269_10_ebad27df76-1.jpeg\">\u003C\u002Fp>\u003Cp>The eligible thread TIDs are:\u003C\u002Fp>\u003Cul>\u003Cli>8136\u003C\u002Fli>\u003Cli>8052\u003C\u002Fli>\u003Cli>6708\u003C\u002Fli>\u003Cli>2316\u003C\u002Fli>\u003Cli>6356\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>4、\u003C\u002Fstrong>End Thread\u003C\u002Fp>\u003Cp>Call TerminateThread\u003C\u002Fp>\u003Cp>Implemented in C++, partial code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>int main(int argc, char* argv[])\u003Cbr>{\t\u003Cbr>\tprintf(\"TerminateThread TID:\\n\");   \t\u003Cbr>\tfor(int i=1;i\u003Cargc;i++)\u003Cbr>\t{\t\u003Cbr>\t\tprintf(\"%s\\n\",argv[i]);\u003Cbr>\t\tHANDLE hThread = OpenThread(0x0001, FALSE,atoi(argv[i]));\u003Cbr>\t\tif(TerminateThread(hThread,0)==0)\u003Cbr>\t\t\tprintf(\"[!] TerminateThread Error, TID: %s \\n\",argv[i]);\u003Cbr>\t\tCloseHandle(hThread);\u003Cbr>\t}  \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fargc;i++)\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The console supports passing multiple parameters. Pass 5 TIDs to it: 8136 8052 6708 2316 6356\u003C\u002Fp>\u003Cp>Automatically terminates the corresponding threads, logging function becomes ineffective\u003C\u002Fp>\u003Cp>Specific operation is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015615284_11_c8420b619e-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Later I will update the complete implementation code for this bypass method on GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Installing Sysmon can extend Windows logging functionality\u003C\u002Fh3>\u003Cp>For related introduction and bypass techniques, refer to;\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E9%80%9A%E8%BF%87APC%E5%AE%9E%E7%8E%B0Dll%E6%B3%A8%E5%85%A5-%E7%BB%95%E8%BF%87Sysmon%E7%9B%91%E6%8E%A7\u003C\u002Fp>\u003Ch3>2. Bypass methods only target Windows Event Logs\u003C\u002Fh3>\u003Cp>Ineffective against Application and Service Logs, such as Windows PowerShell\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616436_12_4f90be3620-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for clearing and bypassing Windows Event Logs, hoping to assist everyone. Next, we will share the specific program implementation for bypass method two.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",324,"Onedaysec",5,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Clear & Bypass Windows Logs: Penetration Testing Techniques","Windows logs, penetration testing, log deletion, log bypass, wevtutil, eventlog, security, system logs, bypass methods, event logging",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1060,1059,1058,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.940Z","2026-07-23T16:02:28.968Z","draft","2026-07-23T16:16:23.428Z"]