Windows Registry ETW Disabled for .NET via COMPlus or ETWEnabled
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
FreeUnreviewedSigmahighv1
windows-registry-etw-disabled-for-net-via-complus-or-etwenabled-a4c90ea1
title: Windows Registry ETW Disabled for .NET via COMPlus or ETWEnabled
id: 2587de6e-b551-42d4-9ba4-645173d44222
related:
- id: bf4fc428-dcc3-4bbd-99fe-2422aeee2544
type: similar
- id: a4c90ea1-2634-4ca0-adbb-35eae169b6fc
type: derived
status: test
description: This rule flags Security Event ID 4657 registry value changes that disable ETW logging for .NET. It matches updates to ETWEnabled under the .NET Framework registry key and COMPlus_ETWEnabled/COMPlus_ETWFlags values under an Environment-related key, with NewValue set to 0. Disabling or impairing ETW can reduce defensive visibility into executed .NET code and actions. The detection relies on Windows Security auditing for registry modifications capturing the affected key paths, value names, and new values.
references:
- https://twitter.com/_xpn_/status/1268712093928378368
- https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr
- https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables
- https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38
- https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39
- https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_
- https://bunnyinside.com/?term=f71e8cb9c76a
- http://managed670.rssing.com/chan-5590147/all_p1.html
- https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code
- https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_dot_net_etw_tamper.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-06-05
modified: 2022-12-20
tags:
- attack.persistence
- attack.defense-impairment
- attack.t1112
- attack.t1685
logsource:
product: windows
service: security
detection:
selection_etw_enabled:
EventID: 4657
ObjectName|endswith: \SOFTWARE\Microsoft\.NETFramework
ObjectValueName: ETWEnabled
NewValue: 0
selection_complus:
EventID: 4657
ObjectName|contains: \Environment
ObjectValueName:
- COMPlus_ETWEnabled
- COMPlus_ETWFlags
NewValue: 0
condition: 1 of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Security Event ID 4657 registry value changes that disable ETW logging for .NET. It matches updates to ETWEnabled under the .NET Framework registry key and COMPlus_ETWEnabled/COMPlus_ETWFlags values under an Environment-related key, with NewValue set to 0. Disabling or impairing ETW can reduce defensive visibility into executed .NET code and actions. The detection relies on Windows Security auditing for registry modifications capturing the affected key paths, value names, and new values.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.