PowerShell ETW Provider Disabling via CommandLine

Rule Info

Name
PowerShell ETW Provider Disabling via CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects attempts to disable or bypass PowerShell Event Tracing for Windows (ETW) via commandline. This technique can be used to evade script block logging and hinder security monitoring.
Date
2026-06-01 00:00:00
Modified
None
Id
a372cc25-d52e-4cc8-a891-57c735f76dac
Tags
attack.defense-impairment attack.t1685.001
Type
Nextron Sigma feed only (private)

Rule History