wevtutil.exe
Summary
Windows Events Utility (wevtutil.exe) is a command-line tool for managing Windows Event Logs. It can query, export, archive, and clear event logs, as well as manage event publishers and subscriptions.
wevtutil.exe is the 157th most commonly executed Windows program in EchoTrail's dataset, observed 105,998 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by MsMpEng.exe.
Behavior
Top Paths
- C:\Windows\System3259.45%
- C:\Windows\SysWOW6440.55%
Top Hashes (SHA256)
- 6a8610238a14c16a03d3d4ab604d3faa31b01243ea809cc2066066cf3551983720.1%
- b2ee960bc90755b5ba89239a50d2311333589fdfc53569b6f57cb43230135add8.58%
- 5de1d5b18e24a8f7294dad0911733f985ae4f9baa01eba9632ce45163d467c926.54%
- 388fde954dd662f4e2a3cda6c6cfb67406a489119dbbfbb55d7fa8aa4172c6656.41%
- c4618dc5b1f77d075b473ae838604acdde73787baab28370bd3efa8e6f70dc075.51%
- be25116a08cca0d57e9247f2aace033bfa1ffb6aa9852f9a9f24dbc2bc32d1874.81%
- e16b9d201ec1d7e29b3ad532a9ad8f1ae0cb5821bb916a79f6dbeb1c6e6b85fa4.19%
- 20db4abf4539d2e054fbadde48078452a5a4adbca9eaeff66aba89f2c91640553.61%
- 5293a95be8f320a3af6d8c1d5e937f13d0ee2925b9b13538487dec0181ef54323.53%
- 1256a1e89815aa5ade26a8fddddeebf056eb3d3a81ebfe0dd73636cc677a3d383.05%
Process Ancestry
Top Grandparents
- OfficeClickToRun.exe42.23%
- Integrator.exe34.22%
- msiexec.exe22.38%
- services.exe0.37%
- cmd.exe0.1%
- explorer.exe0.07%
- drvinst.exe0.05%
- Tvsukernel.exe0.04%
- rundll32.exe0.03%
Top Parents
- MsMpEng.exe24.01%
- Integrator.exe22.12%
- cmd.exe21.37%
- wevtutil.exe19.23%
- msiexec.exe9.44%
- setup.exe1.28%
- svchost.exe0.12%
- powershell.exe0.09%
Top Children
- conhost.exe72.71%
- wevtutil.exe27.26%
- SearchFilterHost.exe0.01%
- chrome.exe<0.01%
- crashpad_handler.exe<0.01%
- drvinst.exe<0.01%
- GoogleDriveFS.exe<0.01%
- iCUE Launcher.exe<0.01%
- OneDrive.exe<0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does wevtutil.exe normally do?
Located in C:\Windows\System32 or C:\Windows\SysWOW64. Launched by MsMpEng.exe (Defender log management), management agents (Integrator.exe), cmd.exe, and can self-spawn. Spawns conhost.exe.
When is wevtutil.exe suspicious?
Clearing event logs: wevtutil cl Security, wevtutil cl System, wevtutil cl Application — classic anti-forensics. Clearing multiple logs in rapid succession. Spawned by unusual parents. Exporting specific security-relevant logs (potential data collection before clearing).
How do attackers abuse wevtutil.exe?
Log clearing: attackers use wevtutil cl to clear Windows Event Logs after an intrusion to remove evidence of their activity. Commonly targets Security, System, and PowerShell logs. This is one of the most recognizable anti-forensics techniques. Log enumeration: wevtutil el to list available logs before selectively clearing them.
Detection guidance
High-confidence: wevtutil cl targeting Security, System, Application, or PowerShell Operational logs. Multiple wevtutil cl commands in sequence (clearing multiple logs). Monitor Windows Event ID 1102 (Security log cleared) and 104 (System log cleared) — these events are generated by the system itself even if the attacker tries to clear logs. Medium-confidence: wevtutil cl targeting any log outside of expected maintenance windows.
False positive notes
Windows Defender (MsMpEng.exe) manages its own event logs via wevtutil. Some management and monitoring tools export and rotate logs using wevtutil. Legitimate log maintenance may clear old logs on a schedule — correlate with change management windows.
Related Processes
Ask Rocky about wevtutil.exe
Rocky answers questions about wevtutil.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.