>_0xFORUM
Sign in

Hunting for disabled ETW providers on endpoints

in Defense9 replies1.4k views

A provider that should be on, off. That is a hunt. Not every off is malice. Some are our own 'perf' tickets.

Inventory expected providers. Then the off is a diff, not a vibe.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 9 REPLIES

I still keep a paper notebook for this kind of note. You wrote «A provider that should be on, off». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

@liveconnect

I still keep a paper notebook for this kind of note. You wrote «A provider that should be on, off». That is the sentence I keep. If debug re

I would have written the opposite conclusion a year ago. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Jump box is not a desktop. No browser, no mail, no Slack. My note id for this: bf-01.

@matrx

I would have written the opposite conclusion a year ago. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on,

If you cannot paste bytes, you do not have a counterexample. This is the writeup I wanted when I was stuck. «Hunting for disabled ETW providers on endpoints» — specifically A provider that should be on, off. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Same class as the June thread, different binary.

This belongs in the first-hour ritual. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Isolate the host too, or stop calling the guest isolated. Was this on the licensed corpus or a crackme you wrote? I wrote a 12-line script and then threw it away. The listing was enough.

@oladipupo

This belongs in the first-hour ritual. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Isolate the

I still keep a paper notebook for this kind of note. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. My note id for this: bf-04.

I disagree with the tone, not the bytes. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I will +rep a listing and −rep a vibe. That is the deal.

@prosmart

I disagree with the tone, not the bytes. On «Hunting for disabled ETW providers on endpoints»: A provider that should be on, off. Except the

Decompiler output is a hypothesis. Treat it like one. Did this on ARM64 last week — same shape, different pain. «Hunting for disabled ETW providers on endpoints» — specifically A provider that should be on, off. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I will +rep a listing and −rep a vibe. That is the deal.

@richkiddo

Did this on ARM64 last week — same shape, different pain. «Hunting for disabled ETW providers on endpoints» — specifically A provider that s

Please keep the hashes and drop the mystery zips. «Hunting for disabled ETW providers on endpoints» — specifically A provider that should be on, off. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and −rep a vibe. That is the deal.

I dumped after OEP and then did this. You wrote «A provider that should be on, off». That is the sentence I keep. 3am isolation notes must fit on a page. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.