Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags

Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.

FreeUnreviewedSigmahighv1
title: "Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags"
id: 433fe994-e8b6-4747-aac5-b6bf47dd7c5b
related:
  - id: a4c90ea1-2634-4ca0-adbb-35eae169b6fc
    type: similar
  - id: bf4fc428-dcc3-4bbd-99fe-2422aeee2544
    type: derived
status: test
description: This rule flags Windows registry changes that disable .NET ETW logging by setting DWORD values to 0 under .NET Framework ETWEnabled and COMPlus ETW-related keys. Attackers may use this to reduce telemetry visibility into loaded .NET assemblies and runtime activity, hindering detection. Telemetry relies on registry set events captured by Sysmon, matching specific TargetObject paths and value types/contents.
references:
  - https://twitter.com/_xpn_/status/1268712093928378368
  - https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr
  - https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables
  - https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38
  - https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39
  - https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_
  - https://bunnyinside.com/?term=f71e8cb9c76a
  - http://managed670.rssing.com/chan-5590147/all_p1.html
  - https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code
  - https://blog.xpnsec.com/hiding-your-dotnet-complus-etwenabled/
  - https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_dot_net_etw_tamper.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-06-05
modified: 2023-08-17
tags:
  - attack.persistence
  - attack.defense-impairment
  - attack.t1112
  - attack.t1685
logsource:
  product: windows
  category: registry_set
detection:
  selection_etw_enabled:
    TargetObject|endswith: SOFTWARE\Microsoft\.NETFramework\ETWEnabled
    Details: DWORD (0x00000000)
  selection_complus:
    TargetObject|endswith:
      - \COMPlus_ETWEnabled
      - \COMPlus_ETWFlags
    Details:
      - 0
      - DWORD (0x00000000)
  condition: 1 of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows registry changes that disable .NET ETW logging by setting DWORD values to 0 under .NET Framework ETWEnabled and COMPlus ETW-related keys. Attackers may use this to reduce telemetry visibility into loaded .NET assemblies and runtime activity, hindering detection. Telemetry relies on registry set events captured by Sysmon, matching specific TargetObject paths and value types/contents.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.