Critical ETW Session Stopped

Rule Info

Name
Critical ETW Session Stopped
Author
Nasreddine Bencherchali (Nextron Systems)
Description
This detection triggers every time an important or critical ETW session is stopped. Attackers can stop ETW sessions in order to blind security monitoring tooling.
Reference
Internal Research
Date
2024-03-13 00:00:00
Modified
None
Id
68d5ec73-c79e-49a4-b75b-59cbdcc4dd11
Tags
attack.defense_evasion
Type
Nextron Sigma feed only (private)

Rule History