Use a module to patch ETW Event Writes in ntdll.dll. This uses the same approach outlined by Adam Chester (https://blog.xpnsec.com/hiding-your-dotnet-etw/)
where the EtwEventWrite function is patched to `ret 14h`.
View Command
To view this TTPs command, you must be logged in with a professional or enterprise license.