Hiding your .NET - ETW
ID: 015f16eb-202a-5d91-8cc8-2d167388ed6f
STIX ID: report--015f16eb-202a-5d91-8cc8-2d167388ed6f
Feed Name: XPN Infosec Blog
This blog post explains how .NET payload execution from unmanaged processes (notably via Cobalt Strike's `execute-assembly`) is exposed to defenders through Event Tracing for Windows (ETW), demonstrates an ETW consumer that reveals loaded assemblies and method names (using SharpHound as an example), and shows how attackers can disable or patch ETW (e.g., patching `ntdll!EtwEventWrite`) to hide or alter telemetry. The author provides code snippets, debugging screenshots, and discusses the cat-and-mouse between defenders using ETW and offensive techniques to evade it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
