About ETW Internals: Architecture, Hooking, Tampering, and Detection
Score: 10/10

About ETW Internals: Architecture, Hooking, Tampering, and Detection

Lazarus, Turla, and other advanced actors utilize kernel-level ETW tampering, including DKOM and hardware breakpoints, to blind EDR and anti-cheat telemetry on Windows 11.

Executive Summary

Event Tracing for Windows (ETW) has become a primary target for sophisticated threat actors like Lazarus and Turla, who aim to suppress high-fidelity security telemetry. The research details how actors move beyond simple user-mode patches to advanced kernel-level techniques, such as Direct Kernel Object Manipulation (DKOM) against the Microsoft-Windows-Threat-Intelligence (ETWTI) provider and the evolution of InfinityHook to bypass recent Microsoft mitigations by targeting downstream HAL timer callbacks.

Technically, the analysis covers the entire ETW lifecycle, from registration entries to session buffer management. It highlights specific tradecraft including the use of hardware breakpoints combined with Vectored Exception Handling (VEH) to achieve 'patchless' bypasses that evade traditional byte-integrity checks. Furthermore, the report identifies how actors like Lazarus (via FudModule) specifically target kernel registration handles in the .data section of ntoskrnl to silence security-critical providers without alerting the EDR to session termination.

For security organizations, this underscores the necessity of a 'defense in depth' approach to telemetry. Relying solely on ETW is insufficient; robust detection must incorporate kernel-callback ledgers (PsSet*, Ob*, Cm*), periodic integrity sweeps of kernel ETW structures, and 'zero-event' behavioral correlation to identify processes that remain active but produce no expected telemetry signals.

Key Details

Threat Name

ETW Internal Architecture and Tampering

Affects

ETW filter object

Adversary

Lazarus Other Adversaries and Aliases: Turla

Malware/Tools

Kazuar, FudModule, EDRSandBlast, InfinityHook, HellsHollow, AceLdr, TamperingSyscalls, SilentMoonwalk, CallStackSpoofer, LayeredSyscall

Report Score

10out of 10
Quality Score
Excellent
IOC Quality8
TTP Details10
Detection Guidance9
Enterprise Relevance10
Clarity & Structure10
Technical Depth10

Sources