面向安全研究与取证的 ETW 内幕
blog.trailofbits.com | 研究 | #threat-intelligence | #malware | #windows | #detection | #trail-of-bits | #etw | #edr | #forensics | #detection-evasion | #threat-intel
摘要
Trail of Bits 深入解析 Windows 事件跟踪(ETW)的内部机制,介绍 provider、consumer 与安全通道如何为 EDR 提供检测情报,说明其为何成为攻击者与恶意软件(如 Lazarus Group 关闭 ETW provider 绕过检测)的常见目标,并探讨其在安全研究与取证中的应用方法。
- 发布时间
- 收录时间
Skip to content