ETW Session Stopped

Rule Info

Name
ETW Session Stopped
Author
Nasreddine Bencherchali (Nextron Systems)
Description
This detection triggers every time an ETW session is stopped. Attackers can stop ETW sessions in order to blind security monitoring tooling.
Reference
Internal Research
Date
2024-03-13 00:00:00
Modified
None
Id
0e57a479-c362-422d-a189-e9661a61064d
Tags
attack.defense_evasion
Type
Nextron Sigma feed only (private)

Rule History