ETW Patching: Detecting Provider-Side Telemetry Tampering
ETW patching attempts to alter an emitting process so expected events no longer reach the trace pipeline. The session and consumer can remain healthy, making end-to-end event expectations and in-memory code integrity essential.
This article omits function targets, offsets, patch bytes, memory-protection commands, and bypass code. It is an integrity and telemetry-health guide.
Where provider-side tampering sits
A process calls an instrumentation path that determines whether a provider is enabled, constructs event data, and hands it to ETW for transport. Tampering within that process may short-circuit emission while unrelated providers and system-wide sessions continue normally. That creates a localized discrepancy: endpoint behavior says the process is active, but its expected provider activity disappears.
Detection engineering
- Compare security-relevant executable pages to the exact signed, patched image after loader fixups.
- Capture page-protection changes and identify the responsible thread or module.
- Model expected event counts per process role, provider, level, keyword, and workload.
- Distinguish provider-local silence from session-wide loss or consumer lag.
- Correlate missing events with process, kernel, script, file, identity, and network telemetry.
Instrumentation libraries may be legitimately hotpatched, hooked by EDR, or modified by profilers and compatibility systems. Validate ranges, signatures, vendor deployment, and call stacks before escalating. Avoid global allowlists based only on a process name.
Forensic workflow
Preserve the emitting process, relevant module pages, page history, threads, stacks, provider registration state, active session configuration, loss counters, and consumer logs. Confirm that the behavior expected to produce an event actually occurred. Compare other processes on the same build to determine whether the difference is local, product-wide, or caused by an update.
Safe lab and GitHub tools
Use a benign custom ETW provider in a disposable VM. Generate known event counts, stop emission through a documented application setting rather than memory modification, and verify that health analytics identify the discrepancy. krabsetw and PerfView support authorized ETW collection; PE-sieve, Moneta, and Volatility 3 support memory integrity analysis.
ATT&CK, CVEs, and controls
ETW patching maps to T1562.001 Impair Defenses. Patching a trace path is a technique, not a CVE; cite vulnerabilities only for verified product-specific flaws. Enforce WDAC, least privilege, EDR tamper protection, current security updates, protected collection services, page-integrity monitoring on high-value processes, provider-volume baselines, and independent telemetry paths.