logo

Hiding your .NET - ETW

ID: 015f16eb-202a-5d91-8cc8-2d167388ed6f

STIX ID: report--015f16eb-202a-5d91-8cc8-2d167388ed6f

Feed Name: XPN Infosec Blog

Threat Score
70/100

Date Published: 2020-03-17

Date Updated: 2026-07-30

...
...

This blog post explains how .NET payload execution from unmanaged processes (notably via Cobalt Strike's `execute-assembly`) is exposed to defenders through Event Tracing for Windows (ETW), demonstrates an ETW consumer that reveals loaded assemblies and method names (using SharpHound as an example), and shows how attackers can disable or patch ETW (e.g., patching `ntdll!EtwEventWrite`) to hide or alter telemetry. The author provides code snippets, debugging screenshots, and discusses the cat-and-mouse between defenders using ETW and offensive techniques to evade it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.