Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Rhysida – wevtutil Log Clearing Paired with ntdsutil NTDS Extraction

Rhysida Defense Evasion Sentinel
MITRE ATT&CK
Indicator Removal
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
CISA AA23-319A (#StopRansomware: Rhysida)
What This Detects
Rhysida is notable for clearing Windows event logs via wevtutil immediately around an ntdsutil NTDS.dit extraction – a combination documented by CISA that is rarely legitimate outside scheduled AD maintenance.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where (FileName =~ "wevtutil.exe" and ProcessCommandLine has "cl ")
   or (FileName =~ "ntdsutil.exe" and ProcessCommandLine has_any ("ifm","create full"))
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.