Executive Summary
Event Tracing for Windows (ETW) has become a primary target for sophisticated threat actors like Lazarus and Turla, who aim to suppress high-fidelity security telemetry. The research details how actors move beyond simple user-mode patches to advanced kernel-level techniques, such as Direct Kernel Object Manipulation (DKOM) against the Microsoft-Windows-Threat-Intelligence (ETWTI) provider and the evolution of InfinityHook to bypass recent Microsoft mitigations by targeting downstream HAL timer callbacks.
Technically, the analysis covers the entire ETW lifecycle, from registration entries to session buffer management. It highlights specific tradecraft including the use of hardware breakpoints combined with Vectored Exception Handling (VEH) to achieve 'patchless' bypasses that evade traditional byte-integrity checks. Furthermore, the report identifies how actors like Lazarus (via FudModule) specifically target kernel registration handles in the .data section of ntoskrnl to silence security-critical providers without alerting the EDR to session termination.
For security organizations, this underscores the necessity of a 'defense in depth' approach to telemetry. Relying solely on ETW is insufficient; robust detection must incorporate kernel-callback ledgers (PsSet*, Ob*, Cm*), periodic integrity sweeps of kernel ETW structures, and 'zero-event' behavioral correlation to identify processes that remain active but produce no expected telemetry signals.
Key Details
Threat Name
ETW Internal Architecture and Tampering
Affects
ETW filter object
Adversary
Lazarus Other Adversaries and Aliases: Turla
Malware/Tools
Kazuar, FudModule, EDRSandBlast, InfinityHook, HellsHollow, AceLdr, TamperingSyscalls, SilentMoonwalk, CallStackSpoofer, LayeredSyscall
