logo

Windows Internals: Check Your Privilege - The Curious Case of ETW’s SecurityTrace Flag

ID: 0480c612-068c-54c1-bb03-244ede02aaaf

STIX ID: report--0480c612-068c-54c1-bb03-244ede02aaaf

Feed Name: Connor McGarr’s Blog

Date Published: 2026-01-16

Date Updated: 2026-04-19

Author: Connor McGarr

...
...

This research analyzes Windows Event Tracing for Windows (ETW) internals, documenting an undocumented SecurityTrace flag used to restrict access to privileged providers (e.g., Microsoft‑Windows‑Threat‑Intelligence) and showing that while queries require Antimalware‑PPL, admin users can still stop such sessions and bypass user‑mode checks to consume events by setting the flag via a unioned `LogBuffersLost` field during `StartTrace` and detouring `ControlTrace` queries. The authors provide a PoC demonstrating consumption of Threat‑Intelligence telemetry without PPL or a kernel driver and report that MSRC does not consider this a vulnerability, recommending moving the SecurityTrace check into the kernel for stronger enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.