Rule Info
Name
ETW Bypass via EtwEventWrite Memory Patch
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Tim Rauch (Nextron Systems)
Description
Detects ETW bypass attempts via memory patching of the EtwEventWrite function in ntdll.dll.
Threat actors may use this technique to evade detection by security tools that rely on ETW for monitoring.
Date
2026-09-30 00:00:00
Modified
None
Id
c4e83de3-2cf8-447e-998f-f02e9baea955
Tags
attack.defense-impairment attack.t1685.001
Type
Nextron Sigma feed only (private)
