Suspicious Windows Trace ETW Session Tamper Via Logman.EXE

 Original Source: [Sigma source]
Title: Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
Status: test
Description:Detects the execution of "logman" utility in order to disable or delete Windows trace sessions
References:
  -https://twitter.com/0gtweet/status/1359039665232306183?s=21
  -https://ss64.com/nt/logman.html
Author: Florian Roth (Nextron Systems)
Date: 2021-02-11
modified:2023-02-21
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
  • -'attack.t1685.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\logman.exe' OriginalFileName:'Logman.exe'   selection_action:
    CommandLine|contains:
      -'stop '
      -'delete '

  selection_service:
    CommandLine|contains:
      -'Circular Kernel Context Logger'
      -'EventLog-'
      -'SYSMON TRACE'
      -'SysmonDnsEtwSession'

  condition:all of selection*
Falsepositives:
  -Legitimate deactivation by administrative staff
  -Installer tools that disable services, e.g. before log collection agent installation
Level: high