[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLuj5jXZi6vMFkNLfXVy9PbhzGjiTZF0QDVg-GWbxIVo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},516,"What is the main approach described in Part 4 for deleting a single EVTX log record from the current system?","Part 4 introduces a technique where the attacker injects a DLL into the Eventlog service process (svchost.exe) to obtain and use the exclusive handle to a specific EVTX log file. Once inside the process, the injected code can modify the log file directly, bypassing the exclusive lock that normally prevents external processes from writing to it. This approach is detailed in [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) – Deleting a Single Log Record from the Current System by Obtaining Log File Handle via Injection](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-4-deleting-a-single-log-record-from-the-current-system-by-obtaining-log-file-handle-via-injection).","\u003Cp>Part 4 introduces a technique where the attacker injects a DLL into the Eventlog service process (svchost.exe) to obtain and use the exclusive handle to a specific EVTX log file. Once inside the process, the injected code can modify the log file directly, bypassing the exclusive lock that normally prevents external processes from writing to it. This approach is detailed in [Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) – Deleting a Single Log Record from the Current System by Obtaining Log File Handle via Injection](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-4-deleting-a-single-log-record-from-the-current-system-by-obtaining-log-file-handle-via-injection).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-entry-deletion-part-4-deleting-a-single-log-record-from-the-current-system-by-obtaining-log-file-handle-via-injection\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-main-approach-described-in-part-4-for-deleting-a-single-evtx-log-rec-1777483291938","DLL injection, Eventlog service, exclusive handle, log file modification",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},128,"Windows XML Event Log (EVTX) Single Log Entry Deletion (Part 4) – Deleting a Single Log Record from the Current System by Obtaining Log File Handle via Injection","windows-xml-event-log-evtx-single-log-entry-deletion-part-4-deleting-a-single-log-record-from-the-current-system-by-obtaining-log-file-handle-via-injection","Learn to delete single EVTX log records by injecting DLL into Eventlog service, obtaining file handles, and modifying logs via memory mapping. Step-by-step guide with code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The fourth article in the Windows XML Event Log (EVTX) single log entry deletion series introduces the second method for deleting a single log record from the current system: obtaining the handle to a specified log file in the Eventlog service process, acquiring operational permissions for that handle via DLL injection, and using the handle to modify the log file.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003Cli>Enumerating all handles in the Eventlog service process to obtain the handle for a specified log file\u003C\u002Fli>\u003Cli>Acquiring operational permissions for the handle via DLL injection\u003C\u002Fli>\u003Cli>Methods for inter-process message passing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the system starts the Eventlog service, it opens log files in exclusive mode, preventing other processes from opening and modifying these log files.\u003C\u002Fp>\u003Cp>So, if we enter the process memory through DLL injection and then obtain the handle to the specified log file, can we gain operational permissions for that log file?\u003C\u002Fp>\u003Ch2>0x03 Enumerate all handles of the Eventlog service process to obtain the handle to the specified log file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use the tool Process Hacker to obtain the handle to the specified log file\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fprocesshacker.sourceforge.io\u002F\u003C\u002Fp>\u003Ch4>(1) Obtain the PID of the Eventlog service process\u003C\u002Fh4>\u003Cp>Execute the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Class win32_service -Filter \"name = 'eventlog'\" | select -exp ProcessId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Run Process Hacker\u003C\u002Fh4>\u003Cp>Locate the process by PID and view Properties-&gt;Handles\u003C\u002Fp>\u003Cp>This allows you to obtain all handle information for the current process\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017964083_0_87602375b3.jpeg\">\u003C\u002Fp>\u003Cp>You can see that the handle value for C:\\Windows\\System32\\winevt\\Logs\\Security.evtx is 0x1c8\u003C\u002Fp>\u003Ch3>2. Obtain the handle of a specified log file through a C++ program\u003C\u002Fh3>\u003Cp>Review the source code of Process Hacker to find the implementation method\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprocesshacker\u002Fprocesshacker\u002Fblob\u002Fe2d793289dede80f6e3bda26d6478dc58b20b7f8\u002FProcessHacker\u002Fhndlprv.c#L307\u003C\u002Fp>\u003Cp>Reference materials obtained:\u003C\u002Fp>\u003Cp>* On Windows 8 and later, NtQueryInformationProcess with ProcessHandleInformation is the most efficient method.\u003C\u002Fp>\u003Cp>* On Windows XP and later, NtQuerySystemInformation with SystemExtendedHandleInformation.\u003C\u002Fp>\u003Cp>* Otherwise, NtQuerySystemInformation with SystemHandleInformation can be used.\u003C\u002Fp>\u003Cp>Therefore, choose the third method for implementation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that the third method is applicable to Windows 7 and later operating systems\u003C\u002Fp>\u003Cp>Using NtQuerySystemInformation to query SystemHandleInformation can obtain handle information for all processes\u003C\u002Fp>\u003Cp>Select all handles in the log process\u003C\u002Fp>\u003Cp>Then use NtDuplicateObject to obtain the handle's name and specific numerical information\u003C\u002Fp>\u003Cp>Finally, filter out the desired handle and output the Handle value\u003C\u002Fp>\u003Cp>The complete implementation code has been open-sourced, download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements searching based on input keywords to obtain corresponding handle names and Handle values\u003C\u002Fp>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017968549_1_3a283b5064.jpeg\">\u003C\u002Fp>\u003Cp>Successfully obtained the pid of the Eventlog service process corresponding to the log, and the Handle value for security.evtx is 0x1c8\u003C\u002Fp>\u003Ch2>0x04 Obtain operation permissions for this handle through DLL injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code for DLL injection via NtCreateThreadEx + LdrLoadDll can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FreeDll is required after successful injection\u003C\u002Fp>\u003Cp>After successful injection, use the obtained Handle value as the first parameter of the function CreateFileMapping() to create a file mapping kernel object\u003C\u002Fp>\u003Cp>Then call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fp>\u003Cp>Next, modify the data in memory to delete a single log record\u003C\u002Fp>\u003Cp>Finally call the function FlushViewOfFile() to write memory data to disk\u003C\u002Fp>\u003Ch2>0x05 Methods for Inter-Process Message Passing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, the entire code implementing the log deletion function must be placed in a DLL. Since CreateRemoteThread cannot pass parameters to the DLL, this makes it impossible to delete logs with a specified EventlogRecordId\u003C\u002Fp>\u003Cp>Here, inter-process message passing can be utilized\u003C\u002Fp>\u003Cp>There are multiple implementation methods, such as signals, pipes, message queues, shared memory, or even reading and writing files\u003C\u002Fp>\u003Cp>Since in\u003Cstrong>0x04\u003C\u002Fstrong>the function CreateFileMapping() was used to create a file mapping kernel object, inter-process message passing also employs the memory mapping method\u003C\u002Fp>\u003Cp>Create a shared memory, code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code creates two memory mapping objects and specifies the access permission for the function CreateFileMapping() to allow anyone to access the object, i.e., the second parameter of the function CreateFileMapping()\u003C\u002Fp>\u003Cp>Typically, this value is set to NULL, indicating default access permissions. However, in the injected DLL, it must be set to allow anyone to access the object; otherwise, an access denied error will occur\u003C\u002Fp>\u003Cp>\u003Cstrong>The reason is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After the DLL is injected into svchost.exe, the permissions are System. Default access permissions cannot access the memory-mapped file object created by the user, so it must be specified to allow anyone to access the object\u003C\u002Fp>\u003Cp>Of course, if it is message passing between two user-privileged processes, the second parameter of the function CreateFileMapping() can be set to NULL.\u003C\u002Fp>\u003Cp>To read the specified shared memory, the code can be referenced as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>In the code, reading these two memory-mapped objects adds the functionality of data type conversion (string to int).\u003C\u002Fp>\u003Ch2>0x06 Program Implementation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Parse the format yourself to implement log deletion.\u003C\u002Fh3>\u003Cp>The key code for deletion is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements the deletion of a log (EventRecordID=14) from the file c:\\test\\Setup.evtx, with the new file saved as c:\\test\\SetupNew.evtx.\u003C\u002Fp>\u003Cp>The entire implementation process is divided into two parts:\u003C\u002Fp>\u003Cul>\u003Cli>Start the program\u003C\u002Fli>\u003Cli>Injected DLL\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Start the program (Loader-rewriting.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the pid of the process corresponding to the Eventlog logging service\u003C\u002Fli>\u003Cli>Enumerate all handles of the process corresponding to the Eventlog logging service to obtain the handle of the specified log file\u003C\u002Fli>\u003Cli>Create two memory mappings to pass the log file handle and the EventRecordID of the log to be deleted to the DLL\u003C\u002Fli>\u003Cli>Inject a DLL into the process corresponding to the Eventlog logging service\u003C\u002Fli>\u003Cli>Release the DLL\u003C\u002Fli>\u003Cli>Close the memory mappings\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>2. The injected DLL (Dll-rewriting.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Read messages from the two memory mappings separately, convert the read content from string to int type to obtain the log file handle and the EventRecordID of the log to be deleted\u003C\u002Fli>\u003Cli>Call the function CreateFileMapping(), passing the log file handle to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify memory data to delete specified logs\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write memory data to disk\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975161_2_10f8432197.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use WinAPI EvtExportLog to filter out the content to be deleted\u003C\u002Fh3>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F360-A-Team\u002FEventCleaner\u002Fblob\u002Fmaster\u002FEventCleaner\u002FEventCleaner.cpp#L528\u003C\u002Fp>\u003Cp>The code I wrote following this approach:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements calling the Windows API EvtExportLog to filter log files, remove specified logs, and save the remaining log content as a new file temp.evtx\u003C\u002Fp>\u003Cp>The entire implementation process is divided into three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Log deletion program\u003C\u002Fli>\u003Cli>Startup program\u003C\u002Fli>\u003Cli>Injected DLL\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Log Deletion Program (DeleteRecord-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code Location:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process as follows:\u003C\u002Fp>\u003Col>\u003Cli>Specify the log file and the EventRecordID of the log to be deleted\u003C\u002Fli>\u003Cli>Generate a new log file temp.evtx\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>2. Launcher Program (Loader-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code Location:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the pid of the process corresponding to the Eventlog service\u003C\u002Fli>\u003Cli>Enumerate all handles of the process corresponding to the Eventlog service to obtain the handle of the specified log file\u003C\u002Fli>\u003Cli>Create three memory mappings to pass the handle of the log file, the length of the new log file, and the content of the new log file to the DLL\u003C\u002Fli>\u003Cli>Inject DLL into the process corresponding to the Eventlog service\u003C\u002Fli>\u003Cli>Release the DLL\u003C\u002Fli>\u003Cli>Close memory mapping\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>3. Injected Dll (Dll-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the handle of the log file from the first memory mapping, convert the read content from string to int type\u003C\u002Fli>\u003Cli>Obtain the length of the new log file from the second memory mapping\u003C\u002Fli>\u003Cli>Adjust the read length of the memory mapping based on the length of the new log file, obtain the content of the new log file from the third memory mapping\u003C\u002Fli>\u003Cli>Call the function CreateFileMapping(), pass in the handle of the log file, create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the memory data, overwrite with the content of the new log file\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017985997_3_a3cdcbddf0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the above two methods, deleting setup.evtx is not problematic, but deleting system.evtx and security.evtx may fail due to race conditions.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced the second method for deleting a single log record in the current system: obtaining the handle of the specified log file in the Eventlog service process, gaining permissions through DLL injection, and using that handle to modify the log file.\u003C\u002Fp>\u003Cp>In some cases, DLL injection may fail. So, is there another method for deleting a single log record in the current system? The next article will introduce it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The fourth article in the Windows XML Event Log (EVTX) single log entry deletion series introduces the second method for deleting a single log record from the current system: obtaining the handle to a specified log file in the Eventlog service process, acquiring operational permissions for that handle via DLL injection, and using the handle to modify the log file.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Approach\u003C\u002Fli>\u003Cli>Program Implementation\u003C\u002Fli>\u003Cli>Enumerating all handles in the Eventlog service process to obtain the handle for a specified log file\u003C\u002Fli>\u003Cli>Acquiring operational permissions for the handle via DLL injection\u003C\u002Fli>\u003Cli>Methods for inter-process message passing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the system starts the Eventlog service, it opens log files in exclusive mode, preventing other processes from opening and modifying these log files.\u003C\u002Fp>\u003Cp>So, if we enter the process memory through DLL injection and then obtain the handle to the specified log file, can we gain operational permissions for that log file?\u003C\u002Fp>\u003Ch2>0x03 Enumerate all handles of the Eventlog service process to obtain the handle to the specified log file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use the tool Process Hacker to obtain the handle to the specified log file\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fprocesshacker.sourceforge.io\u002F\u003C\u002Fp>\u003Ch4>(1) Obtain the PID of the Eventlog service process\u003C\u002Fh4>\u003Cp>Execute the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Class win32_service -Filter \"name = 'eventlog'\" | select -exp ProcessId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Run Process Hacker\u003C\u002Fh4>\u003Cp>Locate the process by PID and view Properties-&gt;Handles\u003C\u002Fp>\u003Cp>This allows you to obtain all handle information for the current process\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017964083_0_87602375b3-1.jpeg\">\u003C\u002Fp>\u003Cp>You can see that the handle value for C:\\Windows\\System32\\winevt\\Logs\\Security.evtx is 0x1c8\u003C\u002Fp>\u003Ch3>2. Obtain the handle of a specified log file through a C++ program\u003C\u002Fh3>\u003Cp>Review the source code of Process Hacker to find the implementation method\u003C\u002Fp>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprocesshacker\u002Fprocesshacker\u002Fblob\u002Fe2d793289dede80f6e3bda26d6478dc58b20b7f8\u002FProcessHacker\u002Fhndlprv.c#L307\u003C\u002Fp>\u003Cp>Reference materials obtained:\u003C\u002Fp>\u003Cp>* On Windows 8 and later, NtQueryInformationProcess with ProcessHandleInformation is the most efficient method.\u003C\u002Fp>\u003Cp>* On Windows XP and later, NtQuerySystemInformation with SystemExtendedHandleInformation.\u003C\u002Fp>\u003Cp>* Otherwise, NtQuerySystemInformation with SystemHandleInformation can be used.\u003C\u002Fp>\u003Cp>Therefore, choose the third method for implementation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Testing shows that the third method is applicable to Windows 7 and later operating systems\u003C\u002Fp>\u003Cp>Using NtQuerySystemInformation to query SystemHandleInformation can obtain handle information for all processes\u003C\u002Fp>\u003Cp>Select all handles in the log process\u003C\u002Fp>\u003Cp>Then use NtDuplicateObject to obtain the handle's name and specific numerical information\u003C\u002Fp>\u003Cp>Finally, filter out the desired handle and output the Handle value\u003C\u002Fp>\u003Cp>The complete implementation code has been open-sourced, download link is as follows:\u003C\u002Fp>\u003Cp>An open-source project).cpp\u003C\u002Fp>\u003Cp>The code implements searching based on input keywords to obtain corresponding handle names and Handle values\u003C\u002Fp>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017968549_1_3a283b5064-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully obtained the pid of the Eventlog service process corresponding to the log, and the Handle value for security.evtx is 0x1c8\u003C\u002Fp>\u003Ch2>0x04 Obtain operation permissions for this handle through DLL injection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code for DLL injection via NtCreateThreadEx + LdrLoadDll can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>FreeDll is required after successful injection\u003C\u002Fp>\u003Cp>After successful injection, use the obtained Handle value as the first parameter of the function CreateFileMapping() to create a file mapping kernel object\u003C\u002Fp>\u003Cp>Then call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fp>\u003Cp>Next, modify the data in memory to delete a single log record\u003C\u002Fp>\u003Cp>Finally call the function FlushViewOfFile() to write memory data to disk\u003C\u002Fp>\u003Ch2>0x05 Methods for Inter-Process Message Passing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, the entire code implementing the log deletion function must be placed in a DLL. Since CreateRemoteThread cannot pass parameters to the DLL, this makes it impossible to delete logs with a specified EventlogRecordId\u003C\u002Fp>\u003Cp>Here, inter-process message passing can be utilized\u003C\u002Fp>\u003Cp>There are multiple implementation methods, such as signals, pipes, message queues, shared memory, or even reading and writing files\u003C\u002Fp>\u003Cp>Since in\u003Cstrong>0x04\u003C\u002Fstrong>the function CreateFileMapping() was used to create a file mapping kernel object, inter-process message passing also employs the memory mapping method\u003C\u002Fp>\u003Cp>Create a shared memory, code can be referenced from:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code creates two memory mapping objects and specifies the access permission for the function CreateFileMapping() to allow anyone to access the object, i.e., the second parameter of the function CreateFileMapping()\u003C\u002Fp>\u003Cp>Typically, this value is set to NULL, indicating default access permissions. However, in the injected DLL, it must be set to allow anyone to access the object; otherwise, an access denied error will occur\u003C\u002Fp>\u003Cp>\u003Cstrong>The reason is as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After the DLL is injected into svchost.exe, the permissions are System. Default access permissions cannot access the memory-mapped file object created by the user, so it must be specified to allow anyone to access the object\u003C\u002Fp>\u003Cp>Of course, if it is message passing between two user-privileged processes, the second parameter of the function CreateFileMapping() can be set to NULL.\u003C\u002Fp>\u003Cp>To read the specified shared memory, the code can be referenced as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>In the code, reading these two memory-mapped objects adds the functionality of data type conversion (string to int).\u003C\u002Fp>\u003Ch2>0x06 Program Implementation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Parse the format yourself to implement log deletion.\u003C\u002Fh3>\u003Cp>The key code for deletion is as follows:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements the deletion of a log (EventRecordID=14) from the file c:\\test\\Setup.evtx, with the new file saved as c:\\test\\SetupNew.evtx.\u003C\u002Fp>\u003Cp>The entire implementation process is divided into two parts:\u003C\u002Fp>\u003Cul>\u003Cli>Start the program\u003C\u002Fli>\u003Cli>Injected DLL\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Start the program (Loader-rewriting.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the pid of the process corresponding to the Eventlog logging service\u003C\u002Fli>\u003Cli>Enumerate all handles of the process corresponding to the Eventlog logging service to obtain the handle of the specified log file\u003C\u002Fli>\u003Cli>Create two memory mappings to pass the log file handle and the EventRecordID of the log to be deleted to the DLL\u003C\u002Fli>\u003Cli>Inject a DLL into the process corresponding to the Eventlog logging service\u003C\u002Fli>\u003Cli>Release the DLL\u003C\u002Fli>\u003Cli>Close the memory mappings\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>2. The injected DLL (Dll-rewriting.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Read messages from the two memory mappings separately, convert the read content from string to int type to obtain the log file handle and the EventRecordID of the log to be deleted\u003C\u002Fli>\u003Cli>Call the function CreateFileMapping(), passing the log file handle to create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify memory data to delete specified logs\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write memory data to disk\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975161_2_10f8432197-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use WinAPI EvtExportLog to filter out the content to be deleted\u003C\u002Fh3>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002F360-A-Team\u002FEventCleaner\u002Fblob\u002Fmaster\u002FEventCleaner\u002FEventCleaner.cpp#L528\u003C\u002Fp>\u003Cp>The code I wrote following this approach:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The code implements calling the Windows API EvtExportLog to filter log files, remove specified logs, and save the remaining log content as a new file temp.evtx\u003C\u002Fp>\u003Cp>The entire implementation process is divided into three parts:\u003C\u002Fp>\u003Cul>\u003Cli>Log deletion program\u003C\u002Fli>\u003Cli>Startup program\u003C\u002Fli>\u003Cli>Injected DLL\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>1. Log Deletion Program (DeleteRecord-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code Location:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process as follows:\u003C\u002Fp>\u003Col>\u003Cli>Specify the log file and the EventRecordID of the log to be deleted\u003C\u002Fli>\u003Cli>Generate a new log file temp.evtx\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>2. Launcher Program (Loader-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code Location:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the pid of the process corresponding to the Eventlog service\u003C\u002Fli>\u003Cli>Enumerate all handles of the process corresponding to the Eventlog service to obtain the handle of the specified log file\u003C\u002Fli>\u003Cli>Create three memory mappings to pass the handle of the log file, the length of the new log file, and the content of the new log file to the DLL\u003C\u002Fli>\u003Cli>Inject DLL into the process corresponding to the Eventlog service\u003C\u002Fli>\u003Cli>Release the DLL\u003C\u002Fli>\u003Cli>Close memory mapping\u003C\u002Fli>\u003C\u002Fol>\u003Ch4>3. Injected Dll (Dll-EvtExportLog.cpp)\u003C\u002Fh4>\u003Cp>Code address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Obtain the handle of the log file from the first memory mapping, convert the read content from string to int type\u003C\u002Fli>\u003Cli>Obtain the length of the new log file from the second memory mapping\u003C\u002Fli>\u003Cli>Adjust the read length of the memory mapping based on the length of the new log file, obtain the content of the new log file from the third memory mapping\u003C\u002Fli>\u003Cli>Call the function CreateFileMapping(), pass in the handle of the log file, create a file mapping kernel object\u003C\u002Fli>\u003Cli>Call the function MapViewOfFile() to map the file data into the process's address space\u003C\u002Fli>\u003Cli>Modify the memory data, overwrite with the content of the new log file\u003C\u002Fli>\u003Cli>Call the function FlushViewOfFile() to write the memory data to disk\u003C\u002Fli>\u003Cli>Close the memory mapping of the log file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017985997_3_a3cdcbddf0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the above two methods, deleting setup.evtx is not problematic, but deleting system.evtx and security.evtx may fail due to race conditions.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced the second method for deleting a single log record in the current system: obtaining the handle of the specified log file in the Eventlog service process, gaining permissions through DLL injection, and using that handle to modify the log file.\u003C\u002Fp>\u003Cp>In some cases, DLL injection may fail. So, is there another method for deleting a single log record in the current system? The next article will introduce it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1059,"Onedaysec",7,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Delete Windows EVTX Log Records via DLL Injection & Handle Manipulation","Windows EVTX, log deletion, DLL injection, Eventlog service, handle manipulation, NtQuerySystemInformation, Process Hacker, inter-process communication, security logs, system forensics",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],519,518,517,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.923Z","2026-07-23T16:01:40.906Z","draft","2026-07-23T16:12:55.288Z"]