logo

ETW Forensics - Why use Event Tracing for Windows over EventLog? -

ID: 0f70b311-081d-5d01-b10d-1ddd38d8487e

STIX ID: report--0f70b311-081d-5d01-b10d-1ddd38d8487e

Feed Name: JPCERT Blog

Date Published: 2024-11-14

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

This report explains the internals of Event Tracing for Windows (ETW), how events are generated and consumed, and the structure of ETW data in memory, then presents a Volatility3 plugin (JPCERTCC/etw-scan) for recovering ETW events from memory images. It shows how to enumerate providers, convert ETL data, and leverage default sessions like LwtNetLog to extract valuable network and security telemetry (e.g., DNS, DHCP, Defender, Threat-Intelligence events) for forensics and incident response. The guidance focuses on practical recovery and parsing workflows to enhance detection and investigation beyond standard Windows EventLogs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.