-
-
Notifications
You must be signed in to change notification settings - Fork 201
Open
Labels
scope: eventsAnything related to kernel eventsAnything related to kernel events
Description
We should supervise the status of the NT Kernel Logger
ETW session periodically. Some threat actors might sweep and end all running ETW sessions on the machine. If the NT kernel session is terminated, we'll try to start a new one and possibly send an alert indicating that the ETW session was stopped.
Metadata
Metadata
Assignees
Labels
scope: eventsAnything related to kernel eventsAnything related to kernel events