Set up the T1070 - Windows Events Logs Cleared playbook
- UpdatedJul 31, 2025
- 2 minutes to read
- Zurich
- Security Incident Response Analysis
Use the following steps to set up the T1070 - Windows Events Logs Cleared playbook.
Before you begin
Role required:
- sn_si.admin
- flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Procedure
icon and select