Hiding your .NET - COMPlus_ETWEnabled
ID: 7caf0c5d-f7a9-559e-80e8-3f378957e8f7
STIX ID: report--7caf0c5d-f7a9-559e-80e8-3f378957e8f7
Feed Name: XPN Infosec Blog
This blog post demonstrates that setting COMPlus_ETWEnabled=0 in the environment causes the .NET CLR to skip registering its ETW providers, allowing attackers to hide in-memory .NET assembly loads from ETW-based telemetry. The author walks through locating the setting in clr.dll, shows relevant control-flow that bypasses EventRegister calls, provides a proof-of-concept for environment-variable spoofing to hide the setting at process launch, and references defensive guidance for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
