Hide Navigation Hide TOC Disable of ETW Trace - Powershell (115fdba9-f017-42e6-84cf-d5573bf2ddf8) Detects usage of powershell cmdlets to disable or remove ETW trace sessions Cluster A Galaxy A Cluster B Galaxy B Level Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Disable of ETW Trace - Powershell (115fdba9-f017-42e6-84cf-d5573bf2ddf8) Sigma-Rules 1 Indicator Blocking - T1562.006 (74d2a63f-3c7b-4852-92da-02d8fbab16da) Attack Pattern Disable of ETW Trace - Powershell (115fdba9-f017-42e6-84cf-d5573bf2ddf8) Sigma-Rules 1 Indicator Blocking - T1562.006 (74d2a63f-3c7b-4852-92da-02d8fbab16da) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2