Patch Windows ETW Event Write function

/static/assets/windows-logo.svg
Use a module to patch ETW Event Writes in ntdll.dll. This uses the same approach outlined by Adam Chester (https://blog.xpnsec.com/hiding-your-dotnet-etw/) where the EtwEventWrite function is patched to `ret 14h`.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)