Closed subvert0r closed 10 months ago
There are many tools that can be used to stop a ETW trace session.
My question is, assuming that we already have a kernel mode driver, what are the possible ways for us to protect our ETW session from getting stopped?
Hi @subvert0r, this a good area to focus on, but it's outside of what the krabsetw project can assist with.
There are many tools that can be used to stop a ETW trace session.
My question is, assuming that we already have a kernel mode driver, what are the possible ways for us to protect our ETW session from getting stopped?