Compliance Node Overview
MITRE ATT&CK T1562.002 (Disable Windows Event Logging) is an Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable Windows event logging to limit data that can be leveraged for detections and audits. Windows event logs record user and system activity such as login attempts, process creation, and much more. This data is used by security tools and analysts to generate detections. The EventLog service maintains event logs from various system components and applications. By default, the service automatically starts when a system powers on. Affected platforms: Windows. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1024 Restrict Registry Permissions, M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1562/002/
SHA-256 integrity: 05ead5e3c1decf4c2dcc541d22c1e002548781118780095a95f860c413fdd750
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1562.002: Disable Windows Event Logging (https://attack.mitre.org/versions/v16/techniques/T1562/002/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access