TGViewer
网络安全笔记 网络安全笔记 @tsecrecord · 7.96K subscribers
Post #1333 2.35K
ETW 取证 - 为什么使用 Windows 事件跟踪而不是 EventLog?

文章指出了 Windows 操作系统日志中的 EventLog 在调查恶意软件感染等安全事件时的局限性,可能无法提供足够的信息。随后介绍了 ETW(Event Tracing for Windows),这是一种可以记录内核和进程生成的事件的系统,用于调试和性能监视,同时也被用于 EDR 产品和防病毒软件的检测逻辑。ETW 能够默认记录操作系统中的各种行为作为事件,因此比 EventLog 提供更多的信息。文章还探讨了如何在没有文件签名的情况下从磁盘或内存中恢复 ETW 事件,并提供了一种从内存映像中恢复 ETW 事件的方法。作者开发了一个名为 etw-scan 的 Volatility3 插件,用于从内存映像中恢复 ETW 事件,并提供了该插件的 GitHub 链接。

https://blogs.jpcert.or.jp/en/2024/11/etw_forensics.html
JPCERT/CC Eyes ETW Forensics - Why use Event Tracing for Windows over EventLog? - - JPCERT/CC Eyes Many people may think of EventLogs when one mentions Windows OS logs. When investigating incidents such as malware infections, it is common to analyze the Windows OS EventLogs to find traces that may help uncover the incident. However, since the...
  • 👍 1
More from @tsecrecord
  1. Sep 27, 2026一款本地数字取证/事件响应辅助工具。该浏览器扩展程序会捕获您调查过程中的屏幕截图(例如 Velociraptor、EDR/SIEM 控制面板、Security Onion、Splu…
  2. Sep 20, 2026https://opsectechniques.com/
  3. Aug 27, 2026https://github.com/hypnguyen1209/log4j2-rce
  4. Aug 15, 2026https://telegra.ph/weekly-408-08-14
  5. Jul 6, 2026The Long Watch — Scenario Select https://mr-r3b00t.github.io/org_cyber_attack_sim/
  6. Jun 24, 2026https://techblog.zozo.com/entry/soc-claude-agent#SOC-Agent%E3%81%AE%E8%A8%AD%E8%A8%88
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →