{"id":339,"date":"2026-09-13T21:32:03","date_gmt":"2026-09-14T01:32:03","guid":{"rendered":"https:\/\/securebydefault.io\/blog\/?p=339"},"modified":"2026-09-13T21:32:03","modified_gmt":"2026-09-14T01:32:03","slug":"soc130-event-log-cleared-powershell-masquerading","status":"publish","type":"post","link":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/","title":{"rendered":"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"376\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg\" alt=\"\" class=\"wp-image-254\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg 720w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend-300x157.jpg 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Alert That Told Me Nothing (And That&#8217;s Exactly Why I Kept Digging)<\/strong><\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-1 wp-block-paragraph\"><strong>The Setup<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">This lab was a fun one because the alert itself barely tells you anything. An Event Log Cleared rule fired on an Exchange server. That&#8217;s it. Here&#8217;s what showed up in the SIEM:<\/p>\n\n\n\n<div class=\"sbd-card\" style=\"\n  background:#0D1E35;\n  border:1px solid #16304f;\n  border-radius:8px;\n  padding:0;\n  max-width:680px;\n  margin:24px auto;\n  font-family:'JetBrains Mono','Courier New',monospace;\n  box-shadow:0 8px 24px rgba(0,0,0,0.35);\n  overflow:hidden;\n\">\n\n  <!-- header bar -->\n  <div style=\"\n    background:#050C18;\n    padding:14px 20px;\n    border-bottom:1px solid #16304f;\n    display:flex;\n    align-items:center;\n    justify-content:space-between;\n  \">\n    <span style=\"\n      color:#00D4FF;\n      font-size:13px;\n      font-weight:700;\n      letter-spacing:1.5px;\n      text-transform:uppercase;\n    \">SOC130 &middot; Event Log Cleared<\/span>\n    <span style=\"\n      color:#8aa0b8;\n      font-size:11px;\n      letter-spacing:1px;\n    \">ALERT DETAILS<\/span>\n  <\/div>\n\n  <!-- field rows -->\n  <div style=\"padding:6px 0;\">\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Event ID<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">64<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Event Time<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">2021-02-21T19:23:10 (+03:00)<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Rule<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">SOC130 &#8211; Event Log Cleared<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Role<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">Security Analyst<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Alert Type<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">Malware<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Difficulty<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">Easy<\/span>\n    <\/div>\n\n    <div style=\"display:flex;align-items:center;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">MITRE ATT&amp;CK<\/span>\n      <span style=\"\n        display:inline-block;\n        background:rgba(0,212,255,0.12);\n        color:#00D4FF;\n        border:1px solid #00D4FF;\n        border-radius:4px;\n        padding:2px 8px;\n        font-size:12px;\n        font-weight:700;\n        letter-spacing:0.5px;\n      \">T1204<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">File Hash<\/span>\n      <span style=\"color:#e8eef5;font-size:12px;word-break:break-all;\">7353f60b1739074eb17c5f4dddefe239<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">File Name<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">powershell.exe<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">File Size<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">437.50 KB<\/span>\n    <\/div>\n\n    <div style=\"display:flex;align-items:center;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Device Action<\/span>\n      <span style=\"\n        display:inline-block;\n        background:rgba(255,196,0,0.12);\n        color:#ffc400;\n        border:1px solid #ffc400;\n        border-radius:4px;\n        padding:2px 8px;\n        font-size:12px;\n        font-weight:700;\n        letter-spacing:0.5px;\n      \">Allowed<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;border-bottom:1px solid #12233d;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Source Address<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">172.16.20.3<\/span>\n    <\/div>\n\n    <div style=\"display:flex;padding:10px 20px;\">\n      <span style=\"flex:0 0 150px;color:#00D4FF;font-size:13px;font-weight:600;\">Source Hostname<\/span>\n      <span style=\"color:#e8eef5;font-size:13px;\">Exchange Server<\/span>\n    <\/div>\n\n  <\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Before I even touched a log, a few things were already bugging me. It&#8217;s an Exchange server, so it&#8217;s sitting right on the edge of the network handling mail for everybody. The rule that fired exists for one reason: catching someone trying to erase their tracks. And the process behind it is powershell.exe, which is about as normal as it gets on a Windows box and also, let&#8217;s be real, the tool every attacker reaches for these days. None of that screams &#8220;compromised&#8221; by itself, but it was enough to make me slow down instead of clicking through it.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-2 wp-block-paragraph\"><strong>Quick Refresher: What &#8216;Log Cleared&#8217; Actually Looks Like<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Before I went hunting through logs, I wanted to know exactly what I was hunting for. There are three Windows event IDs worth knowing here:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>1102 \u2013 someone cleared the Security log<\/li>\n\n\n\n<li>1100 \u2013 the logging service itself got shut off<\/li>\n\n\n\n<li>104 \u2013 logs cleared, but this shows up in the System log instead. Worth knowing because attackers sometimes wipe one and completely forget the other<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Having that in your back pocket saves you time. If Security&#8217;s empty but System shows a 104, that&#8217;s basically the attacker telling on themselves.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-3 wp-block-paragraph\"><strong>The Logs Gave Me Nothing (Which Is Actually Something)<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">First move was pulling up the SIEM and filtering right around the alert&#8217;s timestamp. And, well, nothing came back. Empty. Not a single entry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At first that feels like a dead end, but it&#8217;s really not. If the alert is called Event Log Cleared and then the logs are empty exactly where you&#8217;d expect to see the clearing event&#8230; yeah, that&#8217;s the alert basically confirming itself. No logs doesn&#8217;t mean no activity. If anything it made me more suspicious, not less.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-4 wp-block-paragraph\"><strong>The Endpoint Told a Completely Different Story<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Since the logs weren&#8217;t giving me anything, I switched over to the Endpoint Security dashboard for the Exchange host (172.16.20.3) and started poking around processes, terminal history, and browser history.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The powershell.exe from the alert was right there, and the hash matched what the alert reported. So no, this wasn&#8217;t some phantom entry, it was genuinely running on that machine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the terminal history is where things got interesting. The commands in there weren&#8217;t from the day of the alert at all, they went all the way back to October of the previous year. Months earlier. And they showed someone enumerating users, spinning up a brand new local account called backupUser, and then quietly adding it to a group called backupGroup.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"625\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ExServer_Terminal-1024x625.png\" alt=\"\" class=\"wp-image-342\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ExServer_Terminal-1024x625.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ExServer_Terminal-300x183.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ExServer_Terminal-767x468.png 767w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ExServer_Terminal.png 1045w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Creating an account and folding it into a group with zero ticket, zero change record, zero paper trail anywhere, that&#8217;s a classic persistence move. It&#8217;s how attackers keep a spare key around even after you patch whatever door they originally walked through. And the fact that this happened four months before the alert even fired is the part that really got me. Whoever did this may have had a foothold on this Exchange server for a long time before anyone noticed.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-5 wp-block-paragraph\"><strong>VirusTotal Said Clean. I Didn&#8217;t Buy It.<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Next up, I ran the file hash through VirusTotal. Zero vendors flagged it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"472\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ-1024x472.png\" alt=\"\" class=\"wp-image-343\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ-1024x472.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ-300x138.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ-768x354.png 768w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ-1536x708.png 1536w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/VTotal_ExServ.png 1703w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is the part where I want to grab newer analysts by the shoulders for a second. A clean VirusTotal result just means antivirus vendors haven&#8217;t catalogued it as malicious yet, nothing more than that. It&#8217;s not a verdict, it&#8217;s a snapshot. That matters even more with something like powershell.exe, since it&#8217;s a totally legit Windows binary. Nobody&#8217;s flagging the tool itself, the danger is entirely in what someone tells it to do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So I kept going. The Community tab on VirusTotal pointed to a Joe Sandbox report on the same hash, and that&#8217;s where things clicked. Joe Sandbox called out initial access through the PowerShell executable, conhost.exe spawning to handle console stuff, some evasion tricks (location checks, a sketchy file path), and, this is the big one, the binary was actively enumerating both the System and Security event logs. That lines up perfectly with an alert literally named Event Log Cleared.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-6 wp-block-paragraph\"><strong>Any.run Sealed It<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">I wanted to actually watch this thing run instead of just reading a sandbox summary, so I ran the sample through Any.run for dynamic analysis. Overall verdict came back as malicious activity, but the details told a slightly different story than I was expecting going in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First thing that jumped out: the file wasn&#8217;t running from where PowerShell normally lives. Any.run tracked three separate copies during this run, staged as powershell.exe in both the Desktop and Downloads folders, not System32. The copy on the Desktop (PID 5820) is the one Any.run flagged outright as starting a Microsoft application from an unusual location. That&#8217;s not PowerShell. That&#8217;s something wearing PowerShell&#8217;s name, sitting in more than one place a user would actually look, and hoping nobody checks the path. Classic masquerading.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"587\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5820-1024x587.png\" alt=\"\" class=\"wp-image-344\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5820-1024x587.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5820-300x172.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5820-767x440.png 767w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5820.png 1100w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">The copy on the Desktop, the one Any.run flagged for launching from an unusual location.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"522\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5420-1024x522.png\" alt=\"\" class=\"wp-image-345\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5420-1024x522.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5420-300x153.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5420-767x391.png 767w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/5420.png 1104w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">A second copy of the same fake powershell.exe, staged in Downloads.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">From there, the process did a lot of quiet homework: checking its own PowerShell version and command history, reading the Windows install date, pulling the machine GUID, and checking Internet Explorer&#8217;s security zone settings. None of that is loud or destructive on its own, it&#8217;s the kind of environment fingerprinting a payload does to figure out if it&#8217;s sitting in a sandbox before it decides whether to show its real behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I went looking for the outbound C2 connections the original writeup for this lab described, and honestly, I couldn&#8217;t back that part up. The connections I could see in the report were all tied to msedge.exe and normal Windows services, nothing under a powershell.exe process ID. So I&#8217;m not going to claim confirmed command-and-control traffic here when the data in front of me doesn&#8217;t support it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What I could confirm, and what&#8217;s honestly the stronger find anyway, is that Any.run&#8217;s own threat detection flagged the download itself: a network trojan alert reading Suspected Amazon CDN Associated with Malware Distribution, pointing straight at the S3 bucket the zip file came from.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"356\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ThreatAmazon-1024x356.png\" alt=\"\" class=\"wp-image-346\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ThreatAmazon-1024x356.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ThreatAmazon-300x104.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ThreatAmazon-765x266.png 765w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/ThreatAmazon.png 1102w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So instead of &#8220;PowerShell phoned home to five IPs,&#8221; the real story is: a file masquerading as PowerShell, launched from a user&#8217;s Downloads folder, fingerprinting the machine it landed on, delivered from infrastructure Any.run already associates with malware distribution. That&#8217;s plenty on its own.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-7 wp-block-paragraph\"><strong>Time to Pull the Plug<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Cleared logs, a sandbox verdict of malicious, a backdoor account built months in advance, and live outbound traffic during execution. That&#8217;s more than enough to justify isolating the box, so I contained the Exchange server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I know, taking an Exchange server offline is a headache. Email stops, people notice within about five minutes, and your inbox fills up with &#8220;is mail down??&#8221; messages. But leaving a possibly compromised, internet-facing server phoning home is a much worse Tuesday than an hour of email outage.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-8 wp-block-paragraph\"><strong>Where I Went Off-Script From the Playbook<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">LetsDefend&#8217;s built-in playbook marked two of my calls wrong: it said this wasn&#8217;t actually a true positive, and that the malware wasn&#8217;t malicious. I&#8217;m going to push back on that one a little.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sure, VirusTotal came back clean. But by the time I wrapped this up I had a sandbox report explicitly calling the behavior malicious, a masquerading PowerShell payload launched from a user&#8217;s Downloads folder, delivery infrastructure Any.run already flags for malware distribution, endpoint history showing a persistence mechanism someone built months ahead of time, and logs that went suspiciously silent exactly where they shouldn&#8217;t have. Closing that out as a false positive because one antivirus aggregator said clean is exactly the kind of shortcut that lets real incidents slip through.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;m sticking with my read: true positive, malicious. Tools and analysts disagree sometimes, and when that happens, the move isn&#8217;t to just shrug and go with the automated score. It&#8217;s to write down why you disagree and hand it off for a second opinion.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-9 wp-block-paragraph\"><strong>The Takeaway<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">An empty log where you expected to find one is not the end of the investigation, it&#8217;s the start of it. And a clean scan from one vendor is a data point, not a finish line. Stack up enough small signals, quiet logs, a sketchy new account, a payload wearing the wrong name in the wrong folder, delivery infrastructure with a bad reputation, and the story tells itself way more clearly than any single tool ever will on its own.<br><\/p>\n\n\n\n<div class=\"sbd-callout\" style=\"\n  background:#0D1E35;\n  border:1px solid #16304f;\n  border-radius:8px;\n  max-width:680px;\n  margin:24px auto;\n  font-family:'JetBrains Mono','Courier New',monospace;\n  box-shadow:0 8px 24px rgba(0,0,0,0.35);\n  overflow:hidden;\n\">\n \n  <!-- header bar -->\n  <div style=\"\n    background:#050C18;\n    padding:14px 20px;\n    border-bottom:1px solid #16304f;\n  \">\n    <span style=\"\n      color:#00D4FF;\n      font-size:15px;\n      font-weight:700;\n      letter-spacing:0.5px;\n    \">If You Only Do Three Things<\/span>\n  <\/div>\n \n  <!-- numbered items -->\n  <div style=\"padding:18px 20px;\">\n \n    <div style=\"display:flex;padding:10px 0;border-bottom:1px solid #12233d;\">\n      <span style=\"\n        flex:0 0 28px;\n        color:#00D4FF;\n        font-size:15px;\n        font-weight:700;\n      \">1.<\/span>\n      <span style=\"color:#e8eef5;font-size:14px;line-height:1.5;\">\n        An empty log next to a &#8220;logs cleared&#8221; alert isn&#8217;t a dead end, it&#8217;s confirmation. Go straight to the endpoint.\n      <\/span>\n    <\/div>\n \n    <div style=\"display:flex;padding:10px 0;border-bottom:1px solid #12233d;\">\n      <span style=\"\n        flex:0 0 28px;\n        color:#00D4FF;\n        font-size:15px;\n        font-weight:700;\n      \">2.<\/span>\n      <span style=\"color:#e8eef5;font-size:14px;line-height:1.5;\">\n        Don&#8217;t let one clean VirusTotal result close the case, especially on a dual-use binary like <code style=\"background:rgba(0,212,255,0.1);color:#00D4FF;padding:1px 5px;border-radius:3px;\">powershell.exe<\/code>. Check sandbox and community reports too.\n      <\/span>\n    <\/div>\n \n    <div style=\"display:flex;padding:10px 0;\">\n      <span style=\"\n        flex:0 0 28px;\n        color:#00D4FF;\n        font-size:15px;\n        font-weight:700;\n      \">3.<\/span>\n      <span style=\"color:#e8eef5;font-size:14px;line-height:1.5;\">\n        If your gut and the automated playbook disagree, write down why and escalate it. Don&#8217;t just shrug and take the score.\n      <\/span>\n    <\/div>\n \n  <\/div>\n<\/div>\n\n\n\n<div class=\"sbd-author-card\" style=\"\n  background:#0D1E35;\n  border:1px solid #16304f;\n  border-radius:10px;\n  max-width:680px;\n  margin:24px auto;\n  padding:24px;\n  font-family:'JetBrains Mono','Courier New',monospace;\n  box-shadow:0 8px 24px rgba(0,0,0,0.35);\n\">\n \n  <div style=\"display:flex;align-items:flex-start;gap:18px;\">\n \n    <!-- avatar -->\n    <div style=\"\n      flex:0 0 64px;\n      width:64px;\n      height:64px;\n      border-radius:50%;\n      border:2px solid #00D4FF;\n      display:flex;\n      align-items:center;\n      justify-content:center;\n      background:rgba(0,212,255,0.06);\n    \">\n      <span style=\"color:#00D4FF;font-size:20px;font-weight:700;letter-spacing:0.5px;\">RM<\/span>\n    <\/div>\n \n    <!-- name + tags + bio -->\n    <div style=\"flex:1;min-width:0;\">\n      <div style=\"color:#ffffff;font-size:18px;font-weight:700;margin-bottom:6px;\">\n        Ron Mercier\n      <\/div>\n \n      <div style=\"\n        color:#00D4FF;\n        font-size:12px;\n        font-weight:700;\n        letter-spacing:1px;\n        text-transform:uppercase;\n        margin-bottom:14px;\n      \">\n        CLOUD&nbsp;&nbsp;&middot;&nbsp;&nbsp;CYBERSECURITY&nbsp;&nbsp;&middot;&nbsp;&nbsp;SECUREBYDEFAULT.IO\n      <\/div>\n \n      <p style=\"\n        color:#a9b8ca;\n        font-size:14px;\n        line-height:1.6;\n        margin:0 0 18px 0;\n      \">\n        Ron is a Cloud and Cybersecurity Engineer and the founder of SecureByDefault.io. He writes hands-on security walkthroughs from real investigations, not theory. Follow along for practical blue team content, server hardening guides, and SOC analyst practice.\n      <\/p>\n \n      <!-- buttons -->\n      <div style=\"display:flex;flex-wrap:wrap;gap:10px;\">\n        <a href=\"https:\/\/securebydefault.io\" target=\"_blank\" rel=\"noopener\" style=\"\n          display:inline-block;\n          background:#00D4FF;\n          color:#050C18;\n          font-size:13px;\n          font-weight:700;\n          text-decoration:none;\n          padding:9px 22px;\n          border-radius:20px;\n        \">Visit SecureByDefault.io<\/a>\n \n        <a href=\"#\" target=\"_blank\" rel=\"noopener\" style=\"\n          display:inline-block;\n          background:transparent;\n          color:#00D4FF;\n          font-size:13px;\n          font-weight:700;\n          text-decoration:none;\n          padding:8px 20px;\n          border-radius:20px;\n          border:1px solid #00D4FF;\n        \">LinkedIn<\/a>\n \n        <a href=\"https:\/\/github.com\/RonMercier\" target=\"_blank\" rel=\"noopener\" style=\"\n          display:inline-block;\n          background:transparent;\n          color:#00D4FF;\n          font-size:13px;\n          font-weight:700;\n          text-decoration:none;\n          padding:8px 20px;\n          border-radius:20px;\n          border:1px solid #00D4FF;\n        \">GitHub<\/a>\n      <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[149,148,150],"tags":[146,41,39,145,147,128,40,144],"class_list":["post-339","post","type-post","status-publish","format-standard","hentry","category-powershell-masquerading","category-soc-analyst-walkthrough","category-virustotal-false-negative","tag-blue-team-2","tag-incident-response","tag-letsdefend","tag-malware-analysis-2","tag-mitre-attack","tag-powershell","tag-soc-analyst","tag-windows-logs"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server - SecureByDefault<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SOC130 Walkthrough: Event Log Cleared &amp; Fake PowerShell\" \/>\n<meta property=\"og:description\" content=\"A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/\" \/>\n<meta property=\"og:site_name\" content=\"SecureByDefault\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T01:32:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"720\" \/>\n\t<meta property=\"og:image:height\" content=\"376\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ron Mercier\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ron Mercier\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/\"},\"author\":{\"name\":\"Ron Mercier\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"headline\":\"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server\",\"datePublished\":\"2026-09-14T01:32:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/\"},\"wordCount\":1697,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"image\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"keywords\":[\"blue-team\",\"incident response\",\"LetsDefend\",\"malware-analysis\",\"mitre-attack\",\"PowerShell\",\"SOC analyst\",\"Windows Logs\"],\"articleSection\":[\"PowerShell masquerading\",\"SOC Analyst Walkthrough\",\"VirusTotal false negative\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/\",\"name\":\"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server - SecureByDefault\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"datePublished\":\"2026-09-14T01:32:03+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#primaryimage\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"contentUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"width\":720,\"height\":376},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc130-event-log-cleared-powershell-masquerading\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/\",\"name\":\"SecureByDefault\",\"description\":\"Cloud Security &amp; Cybersecurity for IT Professionals\",\"publisher\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\",\"name\":\"Ron Mercier\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"contentUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"width\":512,\"height\":512,\"caption\":\"Ron Mercier\"},\"logo\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\"},\"sameAs\":[\"https:\\\/\\\/securebydefault.io\\\/blog\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/ron-mercier\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCDyWOTMI23S8Y3zwPoX3UkQ\"],\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/author\\\/sbd_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server - SecureByDefault","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/","og_locale":"en_US","og_type":"article","og_title":"SOC130 Walkthrough: Event Log Cleared & Fake PowerShell","og_description":"A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.","og_url":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/","og_site_name":"SecureByDefault","article_published_time":"2026-09-14T01:32:03+00:00","og_image":[{"width":720,"height":376,"url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","type":"image\/jpeg"}],"author":"Ron Mercier","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ron Mercier","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#article","isPartOf":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/"},"author":{"name":"Ron Mercier","@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"headline":"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server","datePublished":"2026-09-14T01:32:03+00:00","mainEntityOfPage":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/"},"wordCount":1697,"commentCount":0,"publisher":{"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"image":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#primaryimage"},"thumbnailUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","keywords":["blue-team","incident response","LetsDefend","malware-analysis","mitre-attack","PowerShell","SOC analyst","Windows Logs"],"articleSection":["PowerShell masquerading","SOC Analyst Walkthrough","VirusTotal false negative"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/","url":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/","name":"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server - SecureByDefault","isPartOf":{"@id":"https:\/\/securebydefault.io\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#primaryimage"},"image":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#primaryimage"},"thumbnailUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","datePublished":"2026-09-14T01:32:03+00:00","breadcrumb":{"@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#primaryimage","url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","contentUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","width":720,"height":376},{"@type":"BreadcrumbList","@id":"https:\/\/securebydefault.io\/blog\/soc130-event-log-cleared-powershell-masquerading\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securebydefault.io\/blog\/"},{"@type":"ListItem","position":2,"name":"LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server"}]},{"@type":"WebSite","@id":"https:\/\/securebydefault.io\/blog\/#website","url":"https:\/\/securebydefault.io\/blog\/","name":"SecureByDefault","description":"Cloud Security &amp; Cybersecurity for IT Professionals","publisher":{"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securebydefault.io\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8","name":"Ron Mercier","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","contentUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","width":512,"height":512,"caption":"Ron Mercier"},"logo":{"@id":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png"},"sameAs":["https:\/\/securebydefault.io\/blog","https:\/\/www.linkedin.com\/in\/ron-mercier\/","https:\/\/www.youtube.com\/channel\/UCDyWOTMI23S8Y3zwPoX3UkQ"],"url":"https:\/\/securebydefault.io\/blog\/author\/sbd_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/comments?post=339"}],"version-history":[{"count":4,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/339\/revisions"}],"predecessor-version":[{"id":348,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/339\/revisions\/348"}],"wp:attachment":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/media?parent=339"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/categories?post=339"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/tags?post=339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}