[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2z5NO6HZaxk_kyviopZxaUGmQ3GNznR5w2EokZN3mZI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":49,"createdAt":49,"_status":48},73,"What are the three main methods to overwrite the original system log file after modifying it?","The three methods are: (1) Releasing file locks by terminating the EventLog process, replacing the file, and restarting the service; (2) Injecting a DLL into the log process to gain a file handle and modify memory directly; (3) Using `DuplicateHandle` to duplicate a file handle from another process and then overwrite the log file content in memory. Each method has trade-offs—injection may be intercepted, and releasing locks creates EventID 7034\u002F7036 logs. For implementation details, refer to the related series: [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 3)](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries) and subsequent parts.","\u003Cp>The three methods are: (1) Releasing file locks by terminating the EventLog process, replacing the file, and restarting the service; (2) Injecting a DLL into the log process to gain a file handle and modify memory directly; (3) Using `DuplicateHandle` to duplicate a file handle from another process and then overwrite the log file content in memory. Each method has trade-offs—injection may be intercepted, and releasing locks creates EventID 7034\u002F7036 logs. For implementation details, refer to the related series: [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 3)](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries) and subsequent parts.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-three-main-methods-to-overwrite-the-original-system-log-file-after--1777485329445","file handle, injection, DuplicateHandle, overwrite log file, Windows Event Log",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},19,"Penetration Techniques - Deleting Single Windows Log Entries","penetration-techniques-deleting-single-windows-log-entries","Learn techniques for deleting single Windows EVTX log entries in penetration testing, including command-line methods and defensive strategies to secure logs.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Deletion and Bypass of Windows Logs', common methods for clearing and bypassing Windows logs were introduced, but the deletion of single log entries was not mentioned.\u003C\u002Fp>\u003Cp>This time, building on the recently completed series on Windows XML Event Log (EVTX) single log entry deletion, we will introduce specific usage methods for deleting single Windows XML Event Log (EVTX) entries in penetration testing, along with defensive recommendations based on exploitation ideas.\u003C\u002Fp>\u003Cp>Addresses for the Windows XML Event Log (EVTX) single log entry deletion series articles:\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 1) - Deletion Approach and Examples\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 2) - Program Implementation for Deleting Single Log Entries in EVTX Files\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 3) - Deleting Single Log Entries in the Current System by Releasing File Handles\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) - Deleting Single Log Entries in the Current System by Injecting to Obtain Log File Handles\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Deletion (Part 5) – Deleting a Single Log Record from the Current System by Acquiring Log File Handle via DuplicateHandle\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining log information via command line\u003C\u002Fli>\u003Cli>Exporting log files via command line\u003C\u002Fli>\u003Cli>Overwriting the original system file with the modified log file\u003C\u002Fli>\u003Cli>Details and considerations\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining Log Information via Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the last ten logs from Security\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:text \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the first ten Security logs:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:text \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The text view does not output EventRecordID\u003C\u002Fp>\u003Cp>You can obtain the EventRecordID corresponding to the log by viewing the XML format\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:xml \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default view is XML, so the command can be simplified as:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc732848(v=ws.11)\u003C\u002Fp>\u003Ch2>0x03 Exporting Log Files via Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exported log files can be downloaded and opened locally, with the file extension .evtx\u003C\u002Fp>\u003Ch3>1. Export all Security logs and save as 1.evtx\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe epl Security 1.evtx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter logs and save\u003C\u002Fh3>\u003Ch4>(1) Delete a single log entry and save\u003C\u002Fh4>\u003Cp>Delete a single log entry under Security (EventRecordID=1112) and save as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [(EventRecordID!=1112)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Delete multiple log entries and save\u003C\u002Fh4>\u003Cp>\u003Cstrong>1. Filter by EventRecordID\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete multiple log entries under Security (EventRecordID 13030, 13031, and 13032) and save the result as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [(EventRecordID&gt;13032) or (EventRecordID&lt;13030)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Filter by SystemTime\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SystemTime must consider the impact of time zones\u003C\u002Fp>\u003Cp>When querying log information via wevtutil with output format as text, time does not account for time zones\u003C\u002Fp>\u003Cp>When viewing log information via the Windows interface, displayed time also does not account for time zones\u003C\u002Fp>\u003Cp>When querying log information via wevtutil with output format as xml, system time considers time zones\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>Query the time of the most recent log entry via wevtutil with output format as text, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019778586_0_f42cad2600.jpeg\">\u003C\u002Fp>\u003Cp>Date: 2018-08-09T20:22:20.558\u003C\u002Fp>\u003Cp>View the timestamp of the most recent log via the Windows interface, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019788320_1_48ac6728d2.jpeg\">\u003C\u002Fp>\u003Cp>Timestamp: 2018-08-09T20:22:20.558\u003C\u002Fp>\u003Cp>Query the timestamp of the most recent log using wevtutil, with output in XML format, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799517_2_7b705d122e.jpeg\">\u003C\u002Fp>\u003Cp>Timestamp: SystemTime='2018-08-10T03:22:20.558894400Z'\u003C\u002Fp>\u003Cp>Time difference of 7 hours\u003C\u002Fp>\u003Cp>Therefore, when deleting logs for a specified date, it is necessary to view the XML format to obtain the SystemTime\u003C\u002Fp>\u003Cp>Delete logs with SystemTime between 2018-08-10T03:20:00 and 2018-08-10T03:21:00, and save the result as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [TimeCreated[@SystemTime &gt;'2018-08-10T03:21:00' or @SystemTime &lt;'2018-08-10T03:20:00']]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Overwrite the original system file with the modified log file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After deleting one or several log entries, it is necessary to overwrite the original system file with the modified log file\u003C\u002Fp>\u003Cp>The following three methods can be adopted\u003C\u002Fp>\u003Ch3>1. By releasing file locks\u003C\u002Fh3>\u003Cp>For details, refer to 'Windows XML Event Log (EVTX) Single Log Deletion (Part 3) – Deleting a Single Log Record in the Current System by Releasing File Locks' (单条日志清除-三-通过解除文件占用删除当前系统单条日志记录)\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Terminate the log process\u003C\u002Fli>\u003Cli>Release the log file handle\u003C\u002Fli>\u003Cli>Replace the log file\u003C\u002Fli>\u003Cli>Restart the log service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The code in the article requires minor modifications; the modified code can be referenced in:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements terminating the log process, releasing the log file handle, replacing the specified log file, and finally restarting the log service\u003C\u002Fp>\u003Ch3>2. By injection\u003C\u002Fh3>\u003Cp>For details, refer to 'Windows XML Event Log (EVTX) Single Log Deletion (Part 4) – Deleting a Single Log Record in the Current System by Injecting to Obtain the Log File Handle' (单条日志清除-四-通过注入获取日志文件句柄删除当前系统单条日志记录)\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Ch4>(1) Loader\u003C\u002Fh4>\u003Cul>\u003Cli>Inject DLL into log process\u003C\u002Fli>\u003Cli>Create three memory mappings to pass log file handle, new log file length, and new log file content to DLL\u003C\u002Fli>\u003Cli>Release DLL\u003C\u002Fli>\u003Cli>Close memory mapping\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch4>(2) DLL\u003C\u002Fh4>\u003Cul>\u003Cli>Read content from memory mapping to obtain log file handle and new log file content\u003C\u002Fli>\u003Cli>Call function MapViewOfFile() to map file data to process address space\u003C\u002Fli>\u003Cli>Modify memory data, overwriting with new log file content\u003C\u002Fli>\u003Cli>Call function FlushViewOfFile() to write memory data to disk\u003C\u002Fli>\u003Cli>Close memory mapping of log file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch3>3. Via DuplicateHandle\u003C\u002Fh3>\u003Cp>For details, please refer to \"Windows XML Event Log (EVTX) Single Log Deletion (Part 5) – Deleting a Single Log Record in the Current System by Obtaining Log File Handle via DuplicateHandle\" (单条日志清除-五-通过DuplicateHandle获取日志文件句柄删除当前系统单条日志记录).\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Enumerate all processes to obtain the specified file handle.\u003C\u002Fli>\u003Cli>Duplicate the handle using DuplicateHandle.\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space.\u003C\u002Fli>\u003Cli>Modify the memory data, overwriting it with the content of the new log file.\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk.\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch2>0x05 Complete Implementation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Suspend the log thread to prevent the current system from logging further.\u003C\u002Fh3>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code supports three operations: suspend, resume, and kill\u003C\u002Fp>\u003Ch3>2. Filter logs and save them\u003C\u002Fh3>\u003Cp>Two methods\u003C\u002Fp>\u003Ch4>(1) Delete specified logs by filtering conditions\u003C\u002Fh4>\u003Cp>Refer to the content of 0x03 for the method\u003C\u002Fp>\u003Cp>Advantages:\u003C\u002Fp>\u003Cp>Simple and efficient\u003C\u002Fp>\u003Cp>Disadvantages:\u003C\u002Fp>\u003Cp>After deleting specified logs, the EventRecordID of subsequent logs is not updated. By comparing the EventRecordID of each log one by one, the number and time range of deleted logs can be identified\u003C\u002Fp>\u003Ch4>(2) Implement it yourself\u003C\u002Fh4>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The advantage is leaving no trace\u003C\u002Fp>\u003Cp>The disadvantage is that implementation is more complicated, requiring consideration of multiple scenarios and multiple chunks\u003C\u002Fp>\u003Ch3>3. Overwrite the original system log file\u003C\u002Fh3>\u003Cp>Three methods:\u003C\u002Fp>\u003Ch4>(1) By releasing file occupation\u003C\u002Fh4>\u003Cp>In some cases, closing the Eventlog process and restarting the Eventlog service will generate log files located under system, with EventID 7034 and 7036\u003C\u002Fp>\u003Cp>You can choose to suspend the thread immediately after log restart to avoid log recording. Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>When the log process does not exist, the program will keep waiting\u003C\u002Fp>\u003Ch4>(2) Through injection\u003C\u002Fh4>\u003Cp>There are cases where injection fails or is intercepted\u003C\u002Fp>\u003Cp>There are race conditions that cause deletion failure\u003C\u002Fp>\u003Ch4>(3) Through DuplicateHandle\u003C\u002Fh4>\u003Cp>There are race conditions that cause deletion failure\u003C\u002Fp>\u003Cp>In summary, a total of *\u003Cem>2\u003C\u002Fem>3=6** methods for deleting single log entries are introduced\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, configurations for PowerShell versions below v5.0 generate logs when powershell.exe is launched, located at %SystemRoot%\\System32\\Winevt\\Logs\\Windows PowerShell.evtx\u003C\u002Fp>\u003Cp>The logs do not record specific script content but include the startup time of powershell.exe\u003C\u002Fp>\u003Cp>Suspending the logging thread does not prevent the generation of this log\u003C\u002Fp>\u003Cp>It is possible to clear individual entries from this log\u003C\u002Fp>\u003Cp>For bypassing logging in higher versions of PowerShell, refer to the article:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.mdsec.co.uk\u002F2018\u002F06\u002Fexploring-powershell-amsi-and-logging-evasion\u002F\u003C\u002Fp>\u003Ch3>4. Restore the logging thread and resume logging functionality\u003C\u002Fh3>\u003Cp>Reference code available:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When an attacker gains full system permissions, the system's logging functionality may become ineffective, as it can be disabled or modified\u003C\u002Fp>\u003Cp>Therefore, for forensic purposes, logs are no longer reliable; consider regularly backing up logs to a remote server\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the specific usage of Windows XML Event Log (EVTX) single log deletion in penetration testing, providing defense recommendations based on exploitation strategies.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Deletion and Bypass of Windows Logs', common methods for clearing and bypassing Windows logs were introduced, but the deletion of single log entries was not mentioned.\u003C\u002Fp>\u003Cp>This time, building on the recently completed series on Windows XML Event Log (EVTX) single log entry deletion, we will introduce specific usage methods for deleting single Windows XML Event Log (EVTX) entries in penetration testing, along with defensive recommendations based on exploitation ideas.\u003C\u002Fp>\u003Cp>Addresses for the Windows XML Event Log (EVTX) single log entry deletion series articles:\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 1) - Deletion Approach and Examples\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 2) - Program Implementation for Deleting Single Log Entries in EVTX Files\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 3) - Deleting Single Log Entries in the Current System by Releasing File Handles\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) - Deleting Single Log Entries in the Current System by Injecting to Obtain Log File Handles\u003C\u002Fp>\u003Cp>-\u003C\u002Fp>\u003Cp>Windows XML Event Log (EVTX) Single Log Deletion (Part 5) – Deleting a Single Log Record from the Current System by Acquiring Log File Handle via DuplicateHandle\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining log information via command line\u003C\u002Fli>\u003Cli>Exporting log files via command line\u003C\u002Fli>\u003Cli>Overwriting the original system file with the modified log file\u003C\u002Fli>\u003Cli>Details and considerations\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining Log Information via Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the last ten logs from Security\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:text \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the first ten Security logs:\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:text \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The text view does not output EventRecordID\u003C\u002Fp>\u003Cp>You can obtain the EventRecordID corresponding to the log by viewing the XML format\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Ff:xml \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default view is XML, so the command can be simplified as:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe qe Security \u002Frd:true \u002Fc:10\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc732848(v=ws.11)\u003C\u002Fp>\u003Ch2>0x03 Exporting Log Files via Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exported log files can be downloaded and opened locally, with the file extension .evtx\u003C\u002Fp>\u003Ch3>1. Export all Security logs and save as 1.evtx\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil.exe epl Security 1.evtx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter logs and save\u003C\u002Fh3>\u003Ch4>(1) Delete a single log entry and save\u003C\u002Fh4>\u003Cp>Delete a single log entry under Security (EventRecordID=1112) and save as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [(EventRecordID!=1112)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Delete multiple log entries and save\u003C\u002Fh4>\u003Cp>\u003Cstrong>1. Filter by EventRecordID\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete multiple log entries under Security (EventRecordID 13030, 13031, and 13032) and save the result as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [(EventRecordID&gt;13032) or (EventRecordID&lt;13030)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>2. Filter by SystemTime\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SystemTime must consider the impact of time zones\u003C\u002Fp>\u003Cp>When querying log information via wevtutil with output format as text, time does not account for time zones\u003C\u002Fp>\u003Cp>When viewing log information via the Windows interface, displayed time also does not account for time zones\u003C\u002Fp>\u003Cp>When querying log information via wevtutil with output format as xml, system time considers time zones\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>Query the time of the most recent log entry via wevtutil with output format as text, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019778586_0_f42cad2600-1.jpeg\">\u003C\u002Fp>\u003Cp>Date: 2018-08-09T20:22:20.558\u003C\u002Fp>\u003Cp>View the timestamp of the most recent log via the Windows interface, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019788320_1_48ac6728d2-1.jpeg\">\u003C\u002Fp>\u003Cp>Timestamp: 2018-08-09T20:22:20.558\u003C\u002Fp>\u003Cp>Query the timestamp of the most recent log using wevtutil, with output in XML format, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799517_2_7b705d122e-1.jpeg\">\u003C\u002Fp>\u003Cp>Timestamp: SystemTime='2018-08-10T03:22:20.558894400Z'\u003C\u002Fp>\u003Cp>Time difference of 7 hours\u003C\u002Fp>\u003Cp>Therefore, when deleting logs for a specified date, it is necessary to view the XML format to obtain the SystemTime\u003C\u002Fp>\u003Cp>Delete logs with SystemTime between 2018-08-10T03:20:00 and 2018-08-10T03:21:00, and save the result as 1.evtx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil epl Security 1.evtx \"\u002Fq:*[System [TimeCreated[@SystemTime &gt;'2018-08-10T03:21:00' or @SystemTime &lt;'2018-08-10T03:20:00']]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Overwrite the original system file with the modified log file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After deleting one or several log entries, it is necessary to overwrite the original system file with the modified log file\u003C\u002Fp>\u003Cp>The following three methods can be adopted\u003C\u002Fp>\u003Ch3>1. By releasing file locks\u003C\u002Fh3>\u003Cp>For details, refer to 'Windows XML Event Log (EVTX) Single Log Deletion (Part 3) – Deleting a Single Log Record in the Current System by Releasing File Locks' (单条日志清除-三-通过解除文件占用删除当前系统单条日志记录)\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Terminate the log process\u003C\u002Fli>\u003Cli>Release the log file handle\u003C\u002Fli>\u003Cli>Replace the log file\u003C\u002Fli>\u003Cli>Restart the log service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The code in the article requires minor modifications; the modified code can be referenced in:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements terminating the log process, releasing the log file handle, replacing the specified log file, and finally restarting the log service\u003C\u002Fp>\u003Ch3>2. By injection\u003C\u002Fh3>\u003Cp>For details, refer to 'Windows XML Event Log (EVTX) Single Log Deletion (Part 4) – Deleting a Single Log Record in the Current System by Injecting to Obtain the Log File Handle' (单条日志清除-四-通过注入获取日志文件句柄删除当前系统单条日志记录)\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Ch4>(1) Loader\u003C\u002Fh4>\u003Cul>\u003Cli>Inject DLL into log process\u003C\u002Fli>\u003Cli>Create three memory mappings to pass log file handle, new log file length, and new log file content to DLL\u003C\u002Fli>\u003Cli>Release DLL\u003C\u002Fli>\u003Cli>Close memory mapping\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch4>(2) DLL\u003C\u002Fh4>\u003Cul>\u003Cli>Read content from memory mapping to obtain log file handle and new log file content\u003C\u002Fli>\u003Cli>Call function MapViewOfFile() to map file data to process address space\u003C\u002Fli>\u003Cli>Modify memory data, overwriting with new log file content\u003C\u002Fli>\u003Cli>Call function FlushViewOfFile() to write memory data to disk\u003C\u002Fli>\u003Cli>Close memory mapping of log file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch3>3. Via DuplicateHandle\u003C\u002Fh3>\u003Cp>For details, please refer to \"Windows XML Event Log (EVTX) Single Log Deletion (Part 5) – Deleting a Single Log Record in the Current System by Obtaining Log File Handle via DuplicateHandle\" (单条日志清除-五-通过DuplicateHandle获取日志文件句柄删除当前系统单条日志记录).\u003C\u002Fp>\u003Cp>The implementation approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Enumerate all processes to obtain the specified file handle.\u003C\u002Fli>\u003Cli>Duplicate the handle using DuplicateHandle.\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space.\u003C\u002Fli>\u003Cli>Modify the memory data, overwriting it with the content of the new log file.\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk.\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch2>0x05 Complete Implementation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Suspend the log thread to prevent the current system from logging further.\u003C\u002Fh3>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code supports three operations: suspend, resume, and kill\u003C\u002Fp>\u003Ch3>2. Filter logs and save them\u003C\u002Fh3>\u003Cp>Two methods\u003C\u002Fp>\u003Ch4>(1) Delete specified logs by filtering conditions\u003C\u002Fh4>\u003Cp>Refer to the content of 0x03 for the method\u003C\u002Fp>\u003Cp>Advantages:\u003C\u002Fp>\u003Cp>Simple and efficient\u003C\u002Fp>\u003Cp>Disadvantages:\u003C\u002Fp>\u003Cp>After deleting specified logs, the EventRecordID of subsequent logs is not updated. By comparing the EventRecordID of each log one by one, the number and time range of deleted logs can be identified\u003C\u002Fp>\u003Ch4>(2) Implement it yourself\u003C\u002Fh4>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The advantage is leaving no trace\u003C\u002Fp>\u003Cp>The disadvantage is that implementation is more complicated, requiring consideration of multiple scenarios and multiple chunks\u003C\u002Fp>\u003Ch3>3. Overwrite the original system log file\u003C\u002Fh3>\u003Cp>Three methods:\u003C\u002Fp>\u003Ch4>(1) By releasing file occupation\u003C\u002Fh4>\u003Cp>In some cases, closing the Eventlog process and restarting the Eventlog service will generate log files located under system, with EventID 7034 and 7036\u003C\u002Fp>\u003Cp>You can choose to suspend the thread immediately after log restart to avoid log recording. Reference code:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>When the log process does not exist, the program will keep waiting\u003C\u002Fp>\u003Ch4>(2) Through injection\u003C\u002Fh4>\u003Cp>There are cases where injection fails or is intercepted\u003C\u002Fp>\u003Cp>There are race conditions that cause deletion failure\u003C\u002Fp>\u003Ch4>(3) Through DuplicateHandle\u003C\u002Fh4>\u003Cp>There are race conditions that cause deletion failure\u003C\u002Fp>\u003Cp>In summary, a total of *\u003Cem>2\u003C\u002Fem>3=6** methods for deleting single log entries are introduced\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, configurations for PowerShell versions below v5.0 generate logs when powershell.exe is launched, located at %SystemRoot%\\System32\\Winevt\\Logs\\Windows PowerShell.evtx\u003C\u002Fp>\u003Cp>The logs do not record specific script content but include the startup time of powershell.exe\u003C\u002Fp>\u003Cp>Suspending the logging thread does not prevent the generation of this log\u003C\u002Fp>\u003Cp>It is possible to clear individual entries from this log\u003C\u002Fp>\u003Cp>For bypassing logging in higher versions of PowerShell, refer to the article:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.mdsec.co.uk\u002F2018\u002F06\u002Fexploring-powershell-amsi-and-logging-evasion\u002F\u003C\u002Fp>\u003Ch3>4. Restore the logging thread and resume logging functionality\u003C\u002Fh3>\u003Cp>Reference code available:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Ch2>0x06 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When an attacker gains full system permissions, the system's logging functionality may become ineffective, as it can be disabled or modified\u003C\u002Fp>\u003Cp>Therefore, for forensic purposes, logs are no longer reliable; consider regularly backing up logs to a remote server\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the specific usage of Windows XML Event Log (EVTX) single log deletion in penetration testing, providing defense recommendations based on exploitation strategies.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1752,"Onedaysec",7,"published","2026-02-02T08:20:05.025Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Delete Single Windows Log Entries: Penetration Techniques & Defense","Windows log deletion, EVTX single entry, penetration testing, wevtutil, log security, event log manipulation, defensive recommendations",null,false,[],{"docs":43,"hasNextPage":40},[4,44],72,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.626Z","2026-07-23T16:00:57.778Z","draft","2026-07-23T16:03:22.421Z"]