[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7-y5Wx2G-f3n9q8fzeB1t_U7aT2CD9Ah0v8uJqBMK8Q":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},760,"How does the article propose to obtain the handle to the specified log file without injecting into svchost.exe?","The approach uses the kernel API `NtQuerySystemInformation` with `SystemHandleInformation` to enumerate all open handles across processes. It filters for file-type handles, optionally narrows the search to the log service process (e.g., by enumerating services), and then uses `NtDuplicateObject` to retrieve handle names and filter for the target EVTX file. This yields the handle without requiring code injection, as explained in [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 5)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle).","\u003Cp>The approach uses the kernel API `NtQuerySystemInformation` with `SystemHandleInformation` to enumerate all open handles across processes. It filters for file-type handles, optionally narrows the search to the log service process (e.g., by enumerating services), and then uses `NtDuplicateObject` to retrieve handle names and filter for the target EVTX file. This yields the handle without requiring code injection, as explained in [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 5)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-article-propose-to-obtain-the-handle-to-the-specified-log-file-with-1777482022942","NtQuerySystemInformation, SystemHandleInformation, NtDuplicateObject, file handle enumeration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},187,"Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 5) – Deleting a Single Log Entry from the Current System by Obtaining Log File Handle via DuplicateHandle","windows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle","Learn to delete single Windows EVTX log entries by obtaining log file handles via DuplicateHandle and process enumeration techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The fifth article in the Windows Single Log Entry Deletion series introduces the third method for deleting a single log entry from the current system: enumerate all processes in the current system, obtain the handle to the specified log file, duplicate the handle via DuplicateHandle to gain permissions, and use this handle to modify the log file.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003Cli>Enumerating all processes to obtain the specified file handle\u003C\u002Fli>\u003Cli>Duplicating the handle via DuplicateHandle\u003C\u002Fli>\u003Cli>Open-source implementation code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article, 'Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) – Deleting a Single Log Entry from the Current System by Obtaining Log File Handle via Injection' mentioned that under certain conditions, higher versions of Windows do not allow injection into the protected process svchost.exe. So, what should we do if we do not want to stop the logging service?\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - File Recovery and Deletion in Windows Systems', I covered a solution that involves using DuplicateHandle to copy handles, converting 'pseudo-handles' into real handles to gain operational permissions for log files.\u003C\u002Fp>\u003Ch2>0x03 Enumerate all processes to obtain specified file handles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Use the kernel API NtQuerySystemInformation to query SystemHandleInformation and obtain handles from all processes\u003C\u002Fli>\u003Cli>Filter out handles of the file type\u003C\u002Fli>\u003Cli>If the process corresponding to a handle cannot be opened, set a flag and avoid repeatedly opening that process\u003C\u002Fli>\u003Cli>Filter out handles that may cause hangs, using the API WaitForSingleObject for judgment\u003C\u002Fli>\u003Cli>Use NtDuplicateObject to retrieve the name and specific numerical information of handles, filtering out the specified ones\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code reference location:\u003C\u002Fp>\u003Cp>An open-source project).cpp.cpp)\u003C\u002Fp>\u003Cp>The code is applicable to Windows 7 and later operating systems and provides the option to close handles\u003C\u002Fp>\u003Cp>Alternatively, you can first enumerate service information to locate the process corresponding to the log service, narrowing the search scope, and then obtain the handles for log files. The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Enumerate service information to find the process corresponding to the log service\u003C\u002Fli>\u003Cli>Use the kernel API NtQuerySystemInformation to query SystemHandleInformation and obtain handles from all processes\u003C\u002Fli>\u003Cli>Filter out handles from the corresponding log service process\u003C\u002Fli>\u003Cli>Obtain handle names and specific numerical information via NtDuplicateObject, then filter for specified handles\u003C\u002Fli>\u003C\u002Ful>\u003Cp>More efficient, avoids potentially hanging handles\u003C\u002Fp>\u003Cp>Code reference location:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code automatically retrieves the log service process, narrows the search scope, and obtains handles to log files\u003C\u002Fp>\u003Ch2>0x04 Duplicate Handle via DuplicateHandle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After obtaining the log file handle by enumerating processes, it was discovered to be a 'pseudo-handle' for the following reasons:\u003C\u002Fp>\u003Cp>Retrieving specific handle contents requires calling NtDuplicateObject\u003C\u002Fp>\u003Cp>DuplicateObject function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL WINAPI DuplicateHandle(\u003Cbr>  _In_  HANDLE   hSourceProcessHandle,\u003Cbr>  _In_  HANDLE   hSourceHandle,\u003Cbr>  _In_  HANDLE   hTargetProcessHandle,\u003Cbr>  _Out_ LPHANDLE lpTargetHandle,\u003Cbr>  _In_  DWORD    dwDesiredAccess,\u003Cbr>  _In_  BOOL     bInheritHandle,\u003Cbr>  _In_  DWORD    dwOptions\u003Cbr>);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms724251(VS.85).aspx\u003C\u002Fp>\u003Cp>The 7th parameter dwOptions can take two values:\u003C\u002Fp>\u003Cul>\u003Cli>DUPLICATE_CLOSE_SOURCE,0x00000001,Closes the source handle. This occurs regardless of any error status returned.\u003C\u002Fli>\u003Cli>DUPLICATE_SAME_ACCESS,0x00000002,Ignores the dwDesiredAccess parameter. The duplicate handle has the same access as the source handle.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Another reference document:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fddi\u002Fcontent\u002Fntifs\u002Fnf-ntifs-zwduplicateobject\u003C\u002Fp>\u003Cp>Reference information obtained:\u003C\u002Fp>\u003Cp>DUPLICATE_SAME_ATTRIBUTES\tInstead of using the HandleAttributes parameter, copy the attributes from the source handle to the target handle.\u003C\u002Fp>\u003Cp>The reference material does not mention the value of DUPLICATE_SAME_ATTRIBUTES; it is speculated to be 0 here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If readers have better answers or explanations, I hope you can inform me\u003C\u002Fp>\u003Cp>To ensure that calling NtDuplicateObject to traverse handles does not affect other system handles, first set dwOptions to DUPLICATE_SAME_ATTRIBUTES (i.e., 0), obtaining only the handle's attributes\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtDuplicateObject(processHandle, (HANDLE)handle.Handle, GetCurrentProcess(), &amp;dupHandle, 0, 0, 0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After locating the specified log file handle, the next step is to operate on the log file. Here, dwOptions needs to be set to DUPLICATE_SAME_ACCESS, representing a full duplication\u003C\u002Fp>\u003Cp>Usage is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtDuplicateObject(processHandle, (HANDLE)handle.Handle, GetCurrentProcess(), &amp;dupHandle, 0, 0, DUPLICATE_SAME_ACCESS)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>dupHandle has the same permissions as the source handle. When operating on the log file, pass dupHandle to CreateFileMapping\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateFileMapping(dupHandle, NULL, PAGE_READWRITE, 0, 0, NULL);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The remaining log deletion operations can refer to previous series articles\u003C\u002Fp>\u003Cp>The complete code has been open-sourced, including two methods for deleting logs:\u003C\u002Fp>\u003Ch3>1. Parse the format yourself to implement log deletion\u003C\u002Fh3>\u003Cp>Address is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements obtaining a handle to the specified log file, through which operational permissions for the log file are acquired, enabling the deletion of individual log entries from a specified evtx file.\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017235652_0_f7d845cdd6.jpeg\">\u003C\u002Fp>\u003Ch3>2. Using WinAPI EvtExportLog to filter out the content to be deleted\u003C\u002Fh3>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements reading the content of log files at a specified path to overwrite system logs\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017249293_1_6ff9f9d3be.jpeg\">\u003C\u002Fp>\u003Cp>The common approach is to first suspend the logging thread, preventing the system from continuing to collect logs. The code address is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Then read the system log content, delete the specified logs, and save the new logs. The code is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Finally, use DeleteRecordbyGetHandleEx to read the new logs and overwrite the system logs, achieving log deletion\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the above two methods, deleting setup.evtx is not problematic, but deleting system.evtx and security.evtx may fail due to race conditions.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the third method for deleting a single log record from the current system: enumerate all processes in the current system, obtain the handle to the specified log file, duplicate the handle using DuplicateHandle to gain permissions, and utilize this handle to modify the log file.\u003C\u002Fp>\u003Cp>The advantage is that it does not require injecting into the process svchost.exe, thus eliminating the need to consider bypassing protections for process injection, and it does not require inter-process communication, resulting in higher efficiency.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The fifth article in the Windows Single Log Entry Deletion series introduces the third method for deleting a single log entry from the current system: enumerate all processes in the current system, obtain the handle to the specified log file, duplicate the handle via DuplicateHandle to gain permissions, and use this handle to modify the log file.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003Cli>Enumerating all processes to obtain the specified file handle\u003C\u002Fli>\u003Cli>Duplicating the handle via DuplicateHandle\u003C\u002Fli>\u003Cli>Open-source implementation code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article, 'Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) – Deleting a Single Log Entry from the Current System by Obtaining Log File Handle via Injection' mentioned that under certain conditions, higher versions of Windows do not allow injection into the protected process svchost.exe. So, what should we do if we do not want to stop the logging service?\u003C\u002Fp>\u003Cp>In a previous article titled 'Penetration Techniques - File Recovery and Deletion in Windows Systems', I covered a solution that involves using DuplicateHandle to copy handles, converting 'pseudo-handles' into real handles to gain operational permissions for log files.\u003C\u002Fp>\u003Ch2>0x03 Enumerate all processes to obtain specified file handles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Use the kernel API NtQuerySystemInformation to query SystemHandleInformation and obtain handles from all processes\u003C\u002Fli>\u003Cli>Filter out handles of the file type\u003C\u002Fli>\u003Cli>If the process corresponding to a handle cannot be opened, set a flag and avoid repeatedly opening that process\u003C\u002Fli>\u003Cli>Filter out handles that may cause hangs, using the API WaitForSingleObject for judgment\u003C\u002Fli>\u003Cli>Use NtDuplicateObject to retrieve the name and specific numerical information of handles, filtering out the specified ones\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Code reference location:\u003C\u002Fp>\u003Cp>An open-source project).cpp.cpp)\u003C\u002Fp>\u003Cp>The code is applicable to Windows 7 and later operating systems and provides the option to close handles\u003C\u002Fp>\u003Cp>Alternatively, you can first enumerate service information to locate the process corresponding to the log service, narrowing the search scope, and then obtain the handles for log files. The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Enumerate service information to find the process corresponding to the log service\u003C\u002Fli>\u003Cli>Use the kernel API NtQuerySystemInformation to query SystemHandleInformation and obtain handles from all processes\u003C\u002Fli>\u003Cli>Filter out handles from the corresponding log service process\u003C\u002Fli>\u003Cli>Obtain handle names and specific numerical information via NtDuplicateObject, then filter for specified handles\u003C\u002Fli>\u003C\u002Ful>\u003Cp>More efficient, avoids potentially hanging handles\u003C\u002Fp>\u003Cp>Code reference location:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code automatically retrieves the log service process, narrows the search scope, and obtains handles to log files\u003C\u002Fp>\u003Ch2>0x04 Duplicate Handle via DuplicateHandle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After obtaining the log file handle by enumerating processes, it was discovered to be a 'pseudo-handle' for the following reasons:\u003C\u002Fp>\u003Cp>Retrieving specific handle contents requires calling NtDuplicateObject\u003C\u002Fp>\u003Cp>DuplicateObject function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL WINAPI DuplicateHandle(\u003Cbr>  _In_  HANDLE   hSourceProcessHandle,\u003Cbr>  _In_  HANDLE   hSourceHandle,\u003Cbr>  _In_  HANDLE   hTargetProcessHandle,\u003Cbr>  _Out_ LPHANDLE lpTargetHandle,\u003Cbr>  _In_  DWORD    dwDesiredAccess,\u003Cbr>  _In_  BOOL     bInheritHandle,\u003Cbr>  _In_  DWORD    dwOptions\u003Cbr>);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms724251(VS.85).aspx\u003C\u002Fp>\u003Cp>The 7th parameter dwOptions can take two values:\u003C\u002Fp>\u003Cul>\u003Cli>DUPLICATE_CLOSE_SOURCE,0x00000001,Closes the source handle. This occurs regardless of any error status returned.\u003C\u002Fli>\u003Cli>DUPLICATE_SAME_ACCESS,0x00000002,Ignores the dwDesiredAccess parameter. The duplicate handle has the same access as the source handle.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Another reference document:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fddi\u002Fcontent\u002Fntifs\u002Fnf-ntifs-zwduplicateobject\u003C\u002Fp>\u003Cp>Reference information obtained:\u003C\u002Fp>\u003Cp>DUPLICATE_SAME_ATTRIBUTES\tInstead of using the HandleAttributes parameter, copy the attributes from the source handle to the target handle.\u003C\u002Fp>\u003Cp>The reference material does not mention the value of DUPLICATE_SAME_ATTRIBUTES; it is speculated to be 0 here\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If readers have better answers or explanations, I hope you can inform me\u003C\u002Fp>\u003Cp>To ensure that calling NtDuplicateObject to traverse handles does not affect other system handles, first set dwOptions to DUPLICATE_SAME_ATTRIBUTES (i.e., 0), obtaining only the handle's attributes\u003C\u002Fp>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtDuplicateObject(processHandle, (HANDLE)handle.Handle, GetCurrentProcess(), &amp;dupHandle, 0, 0, 0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After locating the specified log file handle, the next step is to operate on the log file. Here, dwOptions needs to be set to DUPLICATE_SAME_ACCESS, representing a full duplication\u003C\u002Fp>\u003Cp>Usage is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtDuplicateObject(processHandle, (HANDLE)handle.Handle, GetCurrentProcess(), &amp;dupHandle, 0, 0, DUPLICATE_SAME_ACCESS)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>dupHandle has the same permissions as the source handle. When operating on the log file, pass dupHandle to CreateFileMapping\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CreateFileMapping(dupHandle, NULL, PAGE_READWRITE, 0, 0, NULL);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The remaining log deletion operations can refer to previous series articles\u003C\u002Fp>\u003Cp>The complete code has been open-sourced, including two methods for deleting logs:\u003C\u002Fp>\u003Ch3>1. Parse the format yourself to implement log deletion\u003C\u002Fh3>\u003Cp>Address is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements obtaining a handle to the specified log file, through which operational permissions for the log file are acquired, enabling the deletion of individual log entries from a specified evtx file.\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017235652_0_f7d845cdd6-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Using WinAPI EvtExportLog to filter out the content to be deleted\u003C\u002Fh3>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements reading the content of log files at a specified path to overwrite system logs\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017249293_1_6ff9f9d3be-1.jpeg\">\u003C\u002Fp>\u003Cp>The common approach is to first suspend the logging thread, preventing the system from continuing to collect logs. The code address is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Then read the system log content, delete the specified logs, and save the new logs. The code is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Finally, use DeleteRecordbyGetHandleEx to read the new logs and overwrite the system logs, achieving log deletion\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the above two methods, deleting setup.evtx is not problematic, but deleting system.evtx and security.evtx may fail due to race conditions.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the third method for deleting a single log record from the current system: enumerate all processes in the current system, obtain the handle to the specified log file, duplicate the handle using DuplicateHandle to gain permissions, and utilize this handle to modify the log file.\u003C\u002Fp>\u003Cp>The advantage is that it does not require injecting into the process svchost.exe, thus eliminating the need to consider bypassing protections for process injection, and it does not require inter-process communication, resulting in higher efficiency.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",763,"Onedaysec",5,"published","2026-02-02T07:38:21.200Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows EVTX Log Entry Deletion via DuplicateHandle Method","Windows EVTX log deletion, DuplicateHandle, log file handle, event log manipulation, process enumeration, NtQuerySystemInformation",null,false,[],{"docs":43,"hasNextPage":40},[31,44,45,4,46],762,761,759,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.594Z","2026-07-23T16:02:03.808Z","draft","2026-07-23T16:14:35.631Z"]