ETW Trace Evasion Activity

 Original Source: [Sigma source]
Title: ETW Trace Evasion Activity
Status: test
Description:Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
References:
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil
  -https://abuse.io/lockergoga.txt
  -https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63
Author: @neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Date: 2019-03-22
modified:2022-06-28
Tags:
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1070'
  • -'attack.t1685'
  • -'car.2016-04-002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_clear_1:
    CommandLine|contains|all:
      -'cl'
      -'/Trace'

  selection_clear_2:
    CommandLine|contains|all:
      -'clear-log'
      -'/Trace'

  selection_disable_1:
    CommandLine|contains|all:
      -'sl'
      -'/e:false'

  selection_disable_2:
    CommandLine|contains|all:
      -'set-log'
      -'/e:false'

  selection_disable_3:
    CommandLine|contains|all:
      -'logman'
      -'update'
      -'trace'
      -'--p'
      -'-ets'

  selection_pwsh_remove:
    CommandLine|contains: 'Remove-EtwTraceProvider'
  selection_pwsh_set:
    CommandLine|contains|all:
      -'Set-EtwTraceProvider'
      -'0x11'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high