Skip to content

<<< Hide Navigation Hide TOC >>>

ETW Logging Tamper In .NET Processes Via CommandLine (41421f44-58f9-455d-838a-c398859841d4)

Detects changes to environment variables related to ETW logging via the CommandLine. This could indicate potential adversaries stopping ETW providers recording loaded .NET assemblies.

Galaxy ColorsAttack Pat...Sigma-Rule...
Rows: 1
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern ETW Logging Tamper In .NET Processes Via CommandLine (41421f44-58f9-455d-838a-c398859841d4) Sigma-Rules 1