Title:
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
Status:
test
Description:Detects the execution of "logman" utility in order to disable or delete Windows trace sessions
References:
-https://twitter.com/0gtweet/status/1359039665232306183?s=21
-https://ss64.com/nt/logman.html
Author: Florian Roth (Nextron Systems)
Date: 2021-02-11
modified:2023-02-21
Tags:
- -'attack.defense-impairment'
- -'attack.t1685'
- -'attack.t1685.005'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\logman.exe'
OriginalFileName:
'Logman.exe'
selection_action:
CommandLine|contains:
-'stop '
-'delete '
selection_service:
CommandLine|contains:
-'Circular Kernel Context Logger'
-'EventLog-'
-'SYSMON TRACE'
-'SysmonDnsEtwSession'
condition:
all of selection*
Falsepositives:
-Legitimate deactivation by administrative staff
-Installer tools that disable services, e.g. before log collection agent installation
Level:
high