Activity timeline
T1685.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 19 reports, and 41 of the 41 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1685.005 Clear Windows Event Logs is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1685 Disable or Modify Tools. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 11 critical, 25 high, 5 medium.
Threats that use T1685.005 most often also use T1059.001 PowerShell (26 threats), T1490 Inhibit System Recovery (26 threats), T1489 Service Stop (22 threats), T1078 Valid Accounts (21 threats), T1486 Data Encrypted for Impact (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
21 tracked threat actors appear in the threats that use T1685.005; the most frequent are The Gentlemen (3), VECT (3), ALPHV (2), Anubis (2), BlackCat (2).
Threat actors using it
Tracked threats
The 30 most recent of 41 tracked threats that use T1685.005.
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threatcritical
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…medium
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)high
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…high
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAThigh
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…high
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaShigh
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domainshigh
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…high
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…critical
- HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…high
- Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)high
- Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical…critical
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…high
- HTML Phishing Attachment Uses "Comment Stuffing" to Evade AI-Based Detection (SharePoint/Teams Credential…medium
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…medium
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driverhigh
Parent technique
T1685 Disable or Modify Tools — 750 tracked threats at the technique level.