ETW Provider Disabled via Registry Modification

Detects modifications to Windows Registry keys associated with Event Tracing for Windows (ETW) Autologger configurations or Event Log service configurations. These modifications can be used by adversaries to disable or tamper with event logging mechanisms, effectively blinding security telemetry and evading detection.