ETW vs Sysmon Against C2 Servers - Pentestmag

ETW vs Sysmon Against C2 Servers

Feb 21, 2023

by Damon Mohammedbeger

In this article, I want to talk about my research about ETW and Sysmon and how I can use these events for detection against C2 servers like Cobalt Strike, PoshC2, Sliver and, as always, Metasploit.

So, as a pentester and security researcher, I tried to work on the Blue-Team side (defensive approach) with my own offensive experience, etc.

In this article, I will talk about these things (which was some of my researches from two years ago about detection with a Blue-Teaming approach):

  1. My own tools created with C# for monitoring ETW/Sysmon Events (Real-time) and how can Detect Remote-Thread-Injection Attack via ETW/Sysmon Events to Detect Malware/backdoor or C2 Client Process also Detecting their Traffic!
    1. ETW vs Sysmon against Cobalt Strike
    2. ETW vs Sysmon against PoshC2
    3. ETW vs Sysmon against Sliver
    4. ETW vs Sysmon against Metasploit &‌ talk about some bugs or problems I saw in my tools when as defender you want to use ETW or Sysmon.
  2. Using ETW VirtualMemAlloc Events for Detection
    1. PE MZ bytes Detection via Memory Scanner tool which made by C# and this memory scanner works based on ETW VirtualMemAlloc events.

Before I begin, I want to talk about 2017, because since 2016/2017 I started to work....

March 1, 2023
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

3 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
io games
3 months ago

I will learn this knowledge gradually

Joseph2222
Joseph2222
9 months ago

Just snagged my presentation from this service, and it’s a total win! No more last-minute stress or slides struggle. Buy presentation – https://studyfy.com/service/buy-presentation The design is on point, and the content? Epic. If you’re done with the presentation chaos, this is your go-to. Seriously, check it out – smooth presentations for the win!

fnaf12
fnaf12
1 year ago

I encourage you to participate in poppy playtime whenever you get the chance. This is a wonderful activity for relieving tension and unwinding after a long day.

© HAKIN9 MEDIA SP. Z O.O. SP. K. 2023