Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
FreeUnreviewedSigmahighv1
sysmon-registry-net-etwenabled-disabled-via-complus-etw-flags-bf4fc428
title: "Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags"
id: 433fe994-e8b6-4747-aac5-b6bf47dd7c5b
related:
- id: a4c90ea1-2634-4ca0-adbb-35eae169b6fc
type: similar
- id: bf4fc428-dcc3-4bbd-99fe-2422aeee2544
type: derived
status: test
description: This rule flags Windows registry changes that disable .NET ETW logging by setting DWORD values to 0 under .NET Framework ETWEnabled and COMPlus ETW-related keys. Attackers may use this to reduce telemetry visibility into loaded .NET assemblies and runtime activity, hindering detection. Telemetry relies on registry set events captured by Sysmon, matching specific TargetObject paths and value types/contents.
references:
- https://twitter.com/_xpn_/status/1268712093928378368
- https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr
- https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables
- https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38
- https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39
- https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_
- https://bunnyinside.com/?term=f71e8cb9c76a
- http://managed670.rssing.com/chan-5590147/all_p1.html
- https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code
- https://blog.xpnsec.com/hiding-your-dotnet-complus-etwenabled/
- https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_dot_net_etw_tamper.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-06-05
modified: 2023-08-17
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
- attack.t1685
logsource:
product: windows
category: registry_set
detection:
selection_etw_enabled:
TargetObject|endswith: SOFTWARE\Microsoft\.NETFramework\ETWEnabled
Details: DWORD (0x00000000)
selection_complus:
TargetObject|endswith:
- \COMPlus_ETWEnabled
- \COMPlus_ETWFlags
Details:
- 0
- DWORD (0x00000000)
condition: 1 of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Windows registry changes that disable .NET ETW logging by setting DWORD values to 0 under .NET Framework ETWEnabled and COMPlus ETW-related keys. Attackers may use this to reduce telemetry visibility into loaded .NET assemblies and runtime activity, hindering detection. Telemetry relies on registry set events captured by Sysmon, matching specific TargetObject paths and value types/contents.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.