This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
ETW Trace Evasion Activity
Original Source:
[Sigma source]
Title:
ETW Trace Evasion Activity
Status:
test
Description:
Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
References:
-https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil
-https://abuse.io/lockergoga.txt
-https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63
Author:
@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Date:
2019-03-22
modified:
2022-06-28
Tags:
-'attack.stealth'
-'attack.defense-impairment'
-'attack.t1070'
-'attack.t1685'
-'car.2016-04-002'
Logsource:
category: process_creation
product: windows
Detection:
selection_clear_1:
CommandLine|contains|all
:
-'cl'
-'/Trace'
selection_clear_2:
CommandLine|contains|all
:
-'clear-log'
-'/Trace'
selection_disable_1:
CommandLine|contains|all
:
-'sl'
-'/e:false'
selection_disable_2:
CommandLine|contains|all
:
-'set-log'
-'/e:false'
selection_disable_3:
CommandLine|contains|all
:
-'logman'
-'update'
-'trace'
-'--p'
-'-ets'
selection_pwsh_remove:
CommandLine|contains
:
'Remove-EtwTraceProvider'
selection_pwsh_set:
CommandLine|contains|all
:
-'Set-EtwTraceProvider'
-'0x11'
condition
:
1 of selection_*
Falsepositives:
-Unknown
Level:
high