ETW patching (EtwEventWrite) in PowerShell/.NET loader process
Detects attempts to patch ETW (Event Tracing for Windows) functions such as EtwEventWrite within the memory space of PowerShell or PWSH processes. This is a common technique used by attackers to suppress telemetry and evade security monitoring tools, often associated with bypassing AMSI/ETW logging mechanisms.
Splunk (SPL)

