drop registry transaction log or security evtx csv · detect rapid bulk registry key deletion · identify scripted registry cleanup operations · surface anti-forensic registry wiping patterns · runs locally
4660 object deleted · 4657 value deleted (%%1538) · 4656 delete handle · 60s burst windows
drop security or system evtx csv exports