Windows Internals: Check Your Privilege - The Curious Case of ETW’s SecurityTrace Flag
ID: 0480c612-068c-54c1-bb03-244ede02aaaf
STIX ID: report--0480c612-068c-54c1-bb03-244ede02aaaf
Feed Name: Connor McGarr’s Blog
This research analyzes Windows Event Tracing for Windows (ETW) internals, documenting an undocumented SecurityTrace flag used to restrict access to privileged providers (e.g., Microsoft‑Windows‑Threat‑Intelligence) and showing that while queries require Antimalware‑PPL, admin users can still stop such sessions and bypass user‑mode checks to consume events by setting the flag via a unioned `LogBuffersLost` field during `StartTrace` and detouring `ControlTrace` queries. The authors provide a PoC demonstrating consumption of Threat‑Intelligence telemetry without PPL or a kernel driver and report that MSRC does not consider this a vulnerability, recommending moving the SecurityTrace check into the kernel for stronger enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
