ETW Session Hijacking: Protecting the Telemetry Control Plane
ETW sessions are managed objects with names, owners, providers, filters, buffers, and output modes. Session hijacking targets that control plane by stopping, replacing, or reconfiguring collection. Defenders need configuration baselines and controller attribution, not merely proof that a session name exists.
This guide does not provide session takeover commands, collision techniques, privilege guidance, or methods for suppressing security providers.
Control-plane versus data-plane failure
Provider patching disrupts event production inside a process. Session hijacking instead changes how collection is configured or owned. A familiar session name may remain while its enabled providers, keywords, filters, buffer policy, file destination, clock, or consumer relationship differs from the approved baseline. A replacement can therefore create false reassurance unless configuration and lifecycle events are audited.
Baseline what matters
- Session name, globally unique identity where available, mode, owner, controller process, token, and start time.
- Enabled providers, levels, keywords, event IDs, filters, stack-walk settings, and exclusions.
- Buffer count and size, flush interval, loss counters, file path, rotation, and real-time consumers.
- Expected service dependencies, restart behavior, endpoint build, and security-product version.
- Authorized maintenance windows and signed processes permitted to change collection.
Detection logic
Monitor session start, stop, update, and unexpected controller termination through a sensor that does not rely exclusively on the protected session. Hash normalized configurations and alert on drift in security-critical providers or output. Correlate changes with privileged logons, service-control events, process ancestry, new binaries, token elevation, and a drop in expected events. Distinguish routine reboot, product upgrade, and policy deployment through change records.
Incident response
Preserve the current session inventory before restarting collectors. Capture controller and consumer processes, tokens, service configuration, command context, loaded modules, security-product logs, process creation, and configuration history. Determine the last known-good event and scope the blind interval using Windows logs, kernel telemetry, identity systems, network records, cloud control planes, and neighboring hosts.
Safe lab and GitHub tools
In a disposable VM, create a non-security diagnostic session with a benign provider and document its complete configuration. Stop and restart it only through normal administrative tooling, then verify lifecycle and drift alerts. Do not interact with EDR or protected sessions. PerfView, krabsetw, UIforETW, and Sigma support trace inspection and downstream analytics.
ATT&CK, CVEs, and hardening
Unauthorized session modification maps to T1562.001 Impair Defenses and may involve T1489 Service Stop. Session-management semantics are not inherently a CVE. Cite a CVE only for a confirmed product or OS vulnerability used to obtain control. Restrict trace-control privileges, run collectors under dedicated service identities, enforce service ACLs and application control, monitor configuration drift, centralize events rapidly, auto-recover safely, and retain independent telemetry for blind-spot reconstruction.
Final perspective
An ETW session is a security-sensitive control-plane object. Treat its identity, owner, full configuration, event volume, and lifecycle as monitored assets. A resilient design can both detect the takeover and investigate activity that occurred while the primary stream was incomplete.