# T1685.005 Clear Windows Event Logs

> As of 2026-10-05, T1685.005 (Clear Windows Event Logs) appears in 41 tracked threats, first reported 2026-02-02 and most recently 2026-10-01, with linked actors including The Gentlemen, VECT, ALPHV; it most often appears alongside T1059.001 (PowerShell).

- **Tracked threats:** 41 (11 critical, 25 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-01
- **Threat actors:** 21

## Key facts

- **ID:** T1685.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1685
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1685/005/

## Activity timeline

T1685.005 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 19 reports, and 41 of the 41 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1685.005 Clear Windows Event Logs is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685). Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 11 critical, 25 high, 5 medium.

Threats that use T1685.005 most often also use [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (26 threats), [T1490 Inhibit System Recovery](https://intel.threadlinqs.com/technique/T1490) (26 threats), [T1489 Service Stop](https://intel.threadlinqs.com/technique/T1489) (22 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (21 threats), [T1486 Data Encrypted for Impact](https://intel.threadlinqs.com/technique/T1486) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

21 tracked threat actors appear in the threats that use T1685.005; the most frequent are [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (3), [VECT](https://intel.threadlinqs.com/actor/VECT) (3), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (2), [Anubis](https://intel.threadlinqs.com/actor/Anubis) (2), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (2).

## Threat actors using it

- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [VECT](https://intel.threadlinqs.com/actor/VECT) — 3
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 2
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 2
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 2
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Hyadina](https://intel.threadlinqs.com/actor/Hyadina) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [Nitrogen](https://intel.threadlinqs.com/actor/Nitrogen) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1685.005.

- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…](https://intel.threadlinqs.com/threat/TL-2026-2352) — medium — 2026-09-06
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…](https://intel.threadlinqs.com/threat/TL-2026-1716) — high — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaS](https://intel.threadlinqs.com/threat/TL-2026-1694) — high — 2026-07-25
- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…](https://intel.threadlinqs.com/threat/TL-2026-1649) — critical — 2026-07-23
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…](https://intel.threadlinqs.com/threat/TL-2026-1615) — high — 2026-07-22
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…](https://intel.threadlinqs.com/threat/TL-2026-1579) — critical — 2026-07-20
- [HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…](https://intel.threadlinqs.com/threat/TL-2026-1528) — high — 2026-07-19
- [Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)](https://intel.threadlinqs.com/threat/TL-2026-1521) — high — 2026-07-19
- [Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical…](https://intel.threadlinqs.com/threat/TL-2026-1364) — critical — 2026-07-15
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…](https://intel.threadlinqs.com/threat/TL-2026-1271) — high — 2026-07-13
- [HTML Phishing Attachment Uses "Comment Stuffing" to Evade AI-Based Detection (SharePoint/Teams Credential…](https://intel.threadlinqs.com/threat/TL-2026-1168) — medium — 2026-07-10
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…](https://intel.threadlinqs.com/threat/TL-2026-1166) — medium — 2026-07-10
- [GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver](https://intel.threadlinqs.com/threat/TL-2026-1148) — high — 2026-07-09

## Related CVEs

CVEs referenced by the tracked threats that use T1685.005, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Parent technique

[T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) — 750 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1685.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
