wevtutil.exe
Sources: 300M+ executions observed in the wild.
Summary
Windows Events Utility (wevtutil.exe) is a command-line tool for managing Windows Event Logs. It can query, export, archive, and clear event logs, as well as manage event publishers and subscriptions.
wevtutil.exe is the 157th most commonly executed Windows program in EchoTrail's dataset, observed 105,998 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by MsMpEng.exe.
Get this in your tools
The same record for wevtutil.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/wevtutil.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System3259.45%
- C:\Windows\SysWOW6440.55%
Top Hashes (SHA256)
- 6a8610238a14c16a03d3d4ab604d3faa31b01243ea809cc2066066cf3551983720.1%
- b2ee960bc90755b5ba89239a50d2311333589fdfc53569b6f57cb43230135add8.58%
- 5de1d5b18e24a8f7294dad0911733f985ae4f9baa01eba9632ce45163d467c926.54%
- 388fde954dd662f4e2a3cda6c6cfb67406a489119dbbfbb55d7fa8aa4172c6656.41%
- c4618dc5b1f77d075b473ae838604acdde73787baab28370bd3efa8e6f70dc075.51%
- be25116a08cca0d57e9247f2aace033bfa1ffb6aa9852f9a9f24dbc2bc32d1874.81%
- e16b9d201ec1d7e29b3ad532a9ad8f1ae0cb5821bb916a79f6dbeb1c6e6b85fa4.19%
- 20db4abf4539d2e054fbadde48078452a5a4adbca9eaeff66aba89f2c91640553.61%
- 5293a95be8f320a3af6d8c1d5e937f13d0ee2925b9b13538487dec0181ef54323.53%
- 1256a1e89815aa5ade26a8fddddeebf056eb3d3a81ebfe0dd73636cc677a3d383.05%
Process Ancestry
Top Grandparents
- OfficeClickToRun.exe42.23%
- Integrator.exe34.22%
- msiexec.exe22.38%
- services.exe0.37%
- cmd.exe0.1%
- explorer.exe0.07%
- drvinst.exe0.05%
- Tvsukernel.exe0.04%
- rundll32.exe0.03%
Top Parents
- MsMpEng.exe24.01%
- Integrator.exe22.12%
- cmd.exe21.37%
- wevtutil.exe19.23%
- msiexec.exe9.44%
- setup.exe1.28%
- svchost.exe0.12%
- powershell.exe0.09%
Top Children
- conhost.exe72.71%
- wevtutil.exe27.26%
- SearchFilterHost.exe0.01%
- chrome.exe<0.01%
- crashpad_handler.exe<0.01%
- drvinst.exe<0.01%
- GoogleDriveFS.exe<0.01%
- iCUE Launcher.exe<0.01%
- OneDrive.exe<0.01%
Security Analysis
What does wevtutil.exe normally do?
Located in C:\Windows\System32 or C:\Windows\SysWOW64. Launched by MsMpEng.exe (Defender log management), management agents (Integrator.exe), cmd.exe, and can self-spawn. Spawns conhost.exe.
When is wevtutil.exe suspicious?
Clearing event logs: wevtutil cl Security, wevtutil cl System, wevtutil cl Application — classic anti-forensics. Clearing multiple logs in rapid succession. Spawned by unusual parents. Exporting specific security-relevant logs (potential data collection before clearing).
How do attackers abuse wevtutil.exe?
Log clearing: attackers use wevtutil cl to clear Windows Event Logs after an intrusion to remove evidence of their activity. Commonly targets Security, System, and PowerShell logs. This is one of the most recognizable anti-forensics techniques. Log enumeration: wevtutil el to list available logs before selectively clearing them.
Detection guidance
High-confidence: wevtutil cl targeting Security, System, Application, or PowerShell Operational logs. Multiple wevtutil cl commands in sequence (clearing multiple logs). Monitor Windows Event ID 1102 (Security log cleared) and 104 (System log cleared) — these events are generated by the system itself even if the attacker tries to clear logs. Medium-confidence: wevtutil cl targeting any log outside of expected maintenance windows.
False positive notes
Windows Defender (MsMpEng.exe) manages its own event logs via wevtutil. Some management and monitoring tools export and rotate logs using wevtutil. Legitimate log maintenance may clear old logs on a schedule — correlate with change management windows.
Related Processes
Ask Rocky about wevtutil.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for wevtutil.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.