SIEM

Log Clearing Use Cases

Grouped by Detection Method

MITRE ATT&CK Framework: Indicator Removal on Host (T1070)

Aggregate Count

Blacklist Alert

Whitelist Alert

Levenshtein Score Alert

Rolling Whitelist Alert

Shannon Entropy Score Alert

Threshold Alert

LogSource Examples

Possible False Positives