Sensitive Trace Session Reached Maximum Size

Rule Info

Name
Sensitive Trace Session Reached Maximum Size
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects events where an critical or important ETW session has reached its maximum size. A session reaching its maximum size could lead to events being lost and a temporary blind spot on the system.
Reference
Internal Research
Date
2024-01-24 00:00:00
Modified
None
Id
9a3fab1e-2a50-40b2-8050-6024e8b7b87e
Tags
attack.defense_evasion
Type
Nextron Sigma feed only (private)

Rule History