Event Tracing for Windows (ETW): With Great Data Comes Great Responsibility
The untapped well of information available in the Windows Operating system is a playground for attackers and quenches the thirst of detection engineers. Event Tracing for Windows (ETW) illuminates possibilities under utilized by security professionals. In this talk, Scot Berner (TrustedSec) and Brandon Scullion (SpecterOps) share their methodologies to mine novel techniques from ETW for offensive operations and detection engineering.