logo

Kernel ETW is the best ETW

ID: 9d0cbe64-4762-5fea-9982-26c6f8ea3109

STIX ID: report--9d0cbe64-4762-5fea-9982-26c6f8ea3109

Feed Name: Elastic Security Labs

Date Published: 2024-09-13

Date Updated: 2026-04-27

...
...

This article analyzes Windows kernel ETW telemetry—covering legacy vs. modern event/trace providers, their trustworthiness, and how security teams can enumerate and validate kernel-level audit events. It details methods to extract provider metadata (including TraceLogging and WPP), correlate EtwRegister/EtwWrite calls to specific APIs, and reveals limitations such as failure-only logging patterns. The piece introduces a Ghidra-based script that maps ETW event descriptors to kernel functions, providing practical guidance to improve the reliability and coverage of security telemetry for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.