Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Watch the ETW kernel logger session #48

Open
rabbitstack opened this issue Feb 16, 2021 · 0 comments
Open

Watch the ETW kernel logger session #48

rabbitstack opened this issue Feb 16, 2021 · 0 comments
Labels
scope: kevents Anything related to kernel events

Comments

@rabbitstack
Copy link
Owner

We should supervise the status of the NT Kernel Logger ETW session periodically. Some threat actors might sweep and end all running ETW sessions on the machine. If the NT kernel session is terminated, we'll try to start a new one and possibly send an alert indicating that the ETW session was stopped.

@rabbitstack rabbitstack added the scope: kevents Anything related to kernel events label Feb 16, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
scope: kevents Anything related to kernel events
Projects
None yet
Development

No branches or pull requests

1 participant