ETW internals for security research and forensics
blog.trailofbits.com | research | #threat-intelligence | #malware | #windows | #detection | #trail-of-bits | #etw | #edr | #forensics | #detection-evasion | #threat-intel
Summary
Trail of Bits explains ETW internals — providers, consumers, and secure channels feeding EDR telemetry — and why attackers target ETW to bypass Windows detection and forensics.
- Published
- Collected
Skip to content