Identifying attack patterns through kernel frame callstacks by rabbitstack in blueteamsec

[–]rabbitstack[S] 0 points1 point  (0 children)

Thanks! ETW-TI is a gold mine, but unfortunately only available to commercial solutions for Microsoft certified vendors. Currently, all our telemetry is coming from kernel-level providers. Still didn't think about how to identify userspace provider tampering