Patch Windows ETW Event Write function

Use a module to patch ETW Event Writes in ntdll.dll. This uses the same approach outlined by Adam Chester ( where the EtwEventWrite function is patched to `ret 14h`.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)