This commit is contained in:
cailllev
2025-11-19 23:37:53 +01:00
parent 50ede6f589
commit d06b09ded0
4 changed files with 2282 additions and 2278 deletions
File diff suppressed because it is too large Load Diff
@@ -1,40 +1,39 @@
timestamp_sys,timestamp_etw,src_type,provider_name,event_id,task_info,process_id,thread_id,ppid,pid,targetpid,targettid,message,filepath,cachename,result,vname,name,sigseq,sigsha,commandline,firstparam,secondparam,timestamp_ns,createtime,flags,imagechecksum,mandatorylabel,packagefullname,packagerelativeappid,parentprocessid,parentprocesssequencenumber,processsequencenumber,processtokenelevationtype,processtokeniselevated,securitymitigations,sessionid,timedatestamp,stackbase,stacklimit,startaddr,subprocesstag,tebbase,threadid,userstackbase,userstacklimit,win32startaddr,cycletime,commitcharge,commitpeak,cpucyclecount,exitcode,exittime,handlecount,hardfaultcount,readoperationcount,readtransferkilobytes,tokenelevationtype,writeoperationcount,writetransferkilobytes"2025-11-19 19:51:16.343730900Z","2025-11-19 19:51:16.3437374Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"++ EDRi START MARKER ++",,,,,,,,,,,1763581876343737400,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:17.287575200Z","2025-11-19 19:51:17.3448096Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"++ EDRi START MARKER ++",,,,,,,,,,,1763581877344809600,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:18.197740800Z","2025-11-19 19:51:18.3561017Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"Before decrypting the attack exe from C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\attacks\Injector-standard.exe.enc",,,,,,,,,,,1763581878356101700,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:18.199912800Z","2025-11-19 19:51:18.3585127Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"After decrypting the attack exe",,,,,,,,,,,1763581878358512700,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:19.108607600Z","2025-11-19 19:51:19.3681762Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"Before starting the attack exe",,,,,,,,,,,1763581879368176200,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:20.9763041Z","2025-11-19 19:51:20.9763041Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 1040 svchost.exe",2280,,,"11956 smartscreen.exe",,,"C:\Windows\System32\smartscreen.exe",,,,,,,,,,1763581880976304100,134080554805558624,0,664452,"0x","","",1040,13,3391,3,0,0,1,419447766,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.0413450Z","2025-11-19 19:51:21.0413450Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 5184 explorer.exe",5116,,," 3348 attack-589.exe",,,"C:\Users\Public\Downloads\attack-589.exe",,,,,,,,,,1763581881041345000,134080554806144016,0,0,"0x","","",5184,140,3392,3,0,0,1,1763491559,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.0443828Z","2025-11-19 19:51:21.0443828Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5184 explorer.exe",5116,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581881044382800,,,,,,,,,,,,,,,18446633084044398592,18446633084044374016,140695599400816,0,289797906432,11212,289800192000,289800187904,140695599400816,,,,,,,,,,,,,
"2025-11-19 19:51:21.0568214Z","2025-11-19 19:51:21.0568214Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 3348 attack-589.exe",11212,,," 3100 conhost.exe",,,"C:\Windows\System32\conhost.exe",,,,,,,,,,1763581881056821400,134080554806283315,0,1035098,"0x","","",3348,3392,3393,3,0,0,1,2671108986,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.0581639Z","2025-11-19 19:51:21.0581639Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",11212,,," 3100 conhost.exe",,,,,,,,,,,,,1763581881058163900,,,,,,,,,,,,,,,18446633084006535168,18446633084006510592,140696384751904,0,1013857710080,13484,1013860270080,1013860261888,140696384751904,,,,,,,,,,,,,
"2025-11-19 19:51:20.821877500Z","2025-11-19 19:51:21.2718203Z","myETW","EDRi-Provider",4242,"EDRiTask","12472 EDRi.exe",,,,,,"After starting the attack exe",,,,,,,,,,,1763581881271820300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.4388601Z","2025-11-19 19:51:21.4388601Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",11212,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581881438860100,,,,,,,,,,,,,,,18446633083996708864,18446633083996684288,140712899206080,0,289797914624,11468,289801240576,289801236480,140712899206080,,,,,,,,,,,,,
"2025-11-19 19:51:21.4393533Z","2025-11-19 19:51:21.4393533Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",11212,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581881439353300,,,,,,,,,,,,,,,18446633084049022976,18446633084048998400,140712899206080,0,289797922816,3088,289802289152,289802285056,140712899206080,,,,,,,,,,,,,
"2025-11-19 19:51:21.4394810Z","2025-11-19 19:51:21.4394810Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",3088,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581881439481000,,,,,,,,,,,,,,,18446633084049080320,18446633084049055744,140712899206080,0,289797931008,12904,289803337728,289803333632,140712899206080,,,,,,,,,,,,,
"2025-11-19 19:51:20.974665800Z","2025-11-19 19:51:21.4415712Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Injector started with PID 3348",,,,,,,,,,,1763581881441571200,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.852182900Z","2025-11-19 19:51:22.4165908Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Running 'standard' config",,,,,,,,,,,1763581882416590800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:21.852392100Z","2025-11-19 19:51:22.4168223Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before starting subprocess to inject to",,,,,,,,,,,1763581882416822300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:22.4176543Z","2025-11-19 19:51:22.4176543Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 3348 attack-589.exe",11212,,," 1436 whoami.exe",,,"C:\Windows\System32\whoami.exe",,,,,,,,,,1763581882417654300,134080554818530829,0,160109,"0x","","",3348,3392,3396,3,0,0,1,3602411345,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:22.4206852Z","2025-11-19 19:51:22.4206852Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",11212,,," 1436 whoami.exe",,,,,,,,,,,,,1763581882420685200,,,,,,,,,,,,,,,18446633084049825792,18446633084049801216,140702344617136,0,521061564416,12400,521063104512,521063096320,140702344617136,,,,,,,,,,,,,
"2025-11-19 19:51:21.858891900Z","2025-11-19 19:51:22.4240441Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After starting subprocess with PID 1436",,,,,,,,,,,1763581882424044100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:22.737817600Z","2025-11-19 19:51:23.4006311Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before opening process handle",,,,,,,,,,,1763581883400631100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:22.738077500Z","2025-11-19 19:51:23.4009294Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After opening process handle",,,,,,,,,,,1763581883400929400,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:23.612812600Z","2025-11-19 19:51:24.3728485Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before allocating memory for shellcode",,,,,,,,,,,1763581884372848500,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:23.613174800Z","2025-11-19 19:51:24.3732488Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After allocating memory for shellcode at 000001FF40840000",,,,,,,,,,,1763581884373248800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:24.486948200Z","2025-11-19 19:51:25.3441106Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before writing shellcode to process",,,,,,,,,,,1763581885344110600,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:24.487258200Z","2025-11-19 19:51:25.3444526Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After writing shellcode to process at 000001FF40840000",,,,,,,,,,,1763581885344452600,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:25.362253700Z","2025-11-19 19:51:26.3166701Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before changing memory protection to PAGE_EXECUTE_READ",,,,,,,,,,,1763581886316670100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:25.362529500Z","2025-11-19 19:51:26.3169751Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After changing memory protection to PAGE_EXECUTE_READ",,,,,,,,,,,1763581886316975100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:26.296106600Z","2025-11-19 19:51:27.3019664Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before reading memory to verify write",,,,,,,,,,,1763581887301966400,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:26.296340900Z","2025-11-19 19:51:27.3022001Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Before creating remote thread",,,,,,,,,,,1763581887302200100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:27.3024711Z","2025-11-19 19:51:27.3024711Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 3348 attack-589.exe",11212,,," 1436 whoami.exe",,,,,,,,,,,,,1763581887302471100,,,,,,,,,,,,,,,18446633084051144704,18446633084051120128,2195810680832,0,521061572608,6380,521063628800,521063620608,2195810680832,,,,,,,,,,,,,
"2025-11-19 19:51:26.296634600Z","2025-11-19 19:51:27.3024967Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"After creating remote thread",,,,,,,,,,,1763581887302496700,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:27.3158199Z","2025-11-19 19:51:27.3158199Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 1436 whoami.exe",6380,,,"11148 calc.exe",,,"C:\Windows\System32\calc.exe",,,,,,,,,,1763581887315819900,134080554863097645,0,90741,"0x","","",1436,3396,3397,3,0,0,1,4001445627,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:27.261554400Z","2025-11-19 19:51:28.2771678Z","myETW","Attack-Provider",1337,"AttackTask"," 3348 attack-589.exe",,,,,,"Attack done",,,,,,,,,,,1763581888277167800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 19:51:28.2782317Z","2025-11-19 19:51:28.2782317Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 3348 attack-589.exe",3088,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581888278231700,,,,,,,,,,,,,,,18446633084049022976,18446633084048998400,140712899206080,0,289797922816,3088,289802289152,289802280960,140712899206080,2024057,,,,,,,,,,,,
"2025-11-19 19:51:28.2782317Z","2025-11-19 19:51:28.2782317Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 3348 attack-589.exe",12904,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581888278231700,,,,,,,,,,,,,,,18446633084049080320,18446633084049055744,140712899206080,0,289797931008,12904,289803337728,289803329536,140712899206080,1558590,,,,,,,,,,,,
"2025-11-19 19:51:28.2782336Z","2025-11-19 19:51:28.2782336Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 3348 attack-589.exe",11468,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581888278233700,,,,,,,,,,,,,,,18446633083996708864,18446633083996684288,140712899206080,0,289797914624,11468,289801240576,289801232384,140712899206080,3363869,,,,,,,,,,,,
"2025-11-19 19:51:28.2783990Z","2025-11-19 19:51:28.2783990Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 3348 attack-589.exe",11212,,," 3348 attack-589.exe",,,,,,,,,,,,,1763581888278399000,,,,,,,,,,,,,,,18446633084044398592,18446633084044374016,140695599400816,0,289797906432,11212,289800192000,289800171520,140695599400816,64789380,,,,,,,,,,,,
"2025-11-19 19:51:28.2786366Z","2025-11-19 19:51:28.2786366Z","ETW","Microsoft-Windows-Kernel-Process",2,"ProcessStop Stop "," 3348 attack-589.exe",11212,,," 3348 attack-589.exe",,,"attack-589.exe",,,,,,,,,,1763581888278636600,134080554806144016,,,,,,,,3392,,,,,,,,,,,,,,,,958464,958464,72053875,0,134080554872628582,52,9,0,0,3,48,0
"2025-11-19 19:51:29.1708754Z","2025-11-19 19:51:29.1708754Z","ETW","Microsoft-Windows-Kernel-Process",2,"ProcessStop Stop "," 1436 whoami.exe",6380,,," 1436 whoami.exe",,,"whoami.exe",,,,,,,,,,1763581889170875400,134080554818530829,,,,,,,,3396,,,,,,,,,,,,,,,,1257472,1302528,57157118,3221225477,134080554881460737,83,0,1,3,3,0,0
timestamp_sys,timestamp_etw,src_type,provider_name,event_id,task_info,process_id,thread_id,ppid,pid,targetpid,targettid,message,filepath,cachename,result,vname,name,sigseq,sigsha,commandline,firstparam,secondparam,timestamp_ns,createtime,flags,imagechecksum,mandatorylabel,packagefullname,packagerelativeappid,parentprocessid,parentprocesssequencenumber,processsequencenumber,processtokenelevationtype,processtokeniselevated,securitymitigations,sessionid,timedatestamp,stackbase,stacklimit,startaddr,subprocesstag,tebbase,threadid,userstackbase,userstacklimit,win32startaddr,cycletime,commitcharge,commitpeak,cpucyclecount,exitcode,exittime,handlecount,hardfaultcount,readoperationcount,readtransferkilobytes,tokenelevationtype,writeoperationcount,writetransferkilobytes"2025-11-19 22:37:11.792165000Z","2025-11-19 22:37:11.7170068Z","myETW","EDRi-Provider",4242,"EDRiTask"," 7508 EDRi.exe",,,,,,"++ EDRi START MARKER ++",,,,,,,,,,,1763591831717006800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:16.175848500Z","2025-11-19 22:37:15.7424568Z","myETW","EDRi-Provider",4242,"EDRiTask"," 7508 EDRi.exe",,,,,,"Before decrypting the attack exe from C:\Users\hacker\source\repos\EDR-Introspection\x64\Release\attacks\Injector-standard.exe.enc",,,,,,,,,,,1763591835742456800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:16.182157400Z","2025-11-19 22:37:15.7482493Z","myETW","EDRi-Provider",4242,"EDRiTask"," 7508 EDRi.exe",,,,,,"After decrypting the attack exe",,,,,,,,,,,1763591835748249300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:17.282796100Z","2025-11-19 22:37:16.7589463Z","myETW","EDRi-Provider",4242,"EDRiTask"," 7508 EDRi.exe",,,,,,"Before starting the attack exe",,,,,,,,,,,1763591836758946300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:20.1091605Z","2025-11-19 22:37:20.1091605Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 1040 svchost.exe",4480,,,"13388 smartscreen.exe",,,"C:\Windows\System32\smartscreen.exe",,,,,,,,,,1763591840109160500,134080654409311255,0,664452,"0x","","",1040,13,6623,3,0,0,1,419447766,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:20.1761396Z","2025-11-19 22:37:20.1761396Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 5184 explorer.exe",15136,,," 5604 attack-890.exe",,,"C:\Users\Public\Downloads\attack-890.exe",,,,,,,,,,1763591840176139600,134080654410040405,0,0,"0x","","",5184,140,6624,3,0,0,1,1763491559,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:20.1789263Z","2025-11-19 22:37:20.1789263Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5184 explorer.exe",15136,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591840178926300,,,,,,,,,,,,,,,18446633084027822080,18446633084027797504,140695618865008,0,867488051200,3452,867486007296,867486003200,140695618865008,,,,,,,,,,,,,
"2025-11-19 22:37:20.1912674Z","2025-11-19 22:37:20.1912674Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 5604 attack-890.exe",3452,,,"13300 conhost.exe",,,"C:\Windows\System32\conhost.exe",,,,,,,,,,1763591840191267400,134080654410205145,0,1035098,"0x","","",5604,6624,6625,3,0,0,1,2671108986,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:20.1924430Z","2025-11-19 22:37:20.1924430Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",3452,,,"13300 conhost.exe",,,,,,,,,,,,,1763591840192443000,,,,,,,,,,,,,,,18446633084027535360,18446633084027510784,140696384751904,0,689119371264,4616,689120477184,689120468992,140696384751904,,,,,,,,,,,,,
"2025-11-19 22:37:20.5510805Z","2025-11-19 22:37:20.5510805Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",3452,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591840551080500,,,,,,,,,,,,,,,18446633084029747200,18446633084029722624,140712899206080,0,867488059392,5960,867490070528,867490066432,140712899206080,,,,,,,,,,,,,
"2025-11-19 22:37:20.5515459Z","2025-11-19 22:37:20.5515459Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",5960,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591840551545900,,,,,,,,,,,,,,,18446633084029718528,18446633084029693952,140712899206080,0,867488067584,8672,867491119104,867491115008,140712899206080,,,,,,,,,,,,,
"2025-11-19 22:37:20.5516458Z","2025-11-19 22:37:20.5516458Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",8672,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591840551645800,,,,,,,,,,,,,,,18446633084029460480,18446633084029435904,140712899206080,0,867488075776,12460,867492167680,867492163584,140712899206080,,,,,,,,,,,,,
"2025-11-19 22:37:21.377891300Z","2025-11-19 22:37:20.5537813Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Injector started with PID 5604",,,,,,,,,,,1763591840553781300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:21.477249300Z","2025-11-19 22:37:20.6551680Z","myETW","EDRi-Provider",4242,"EDRiTask"," 7508 EDRi.exe",,,,,,"After starting the attack exe",,,,,,,,,,,1763591840655168000,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:22.337559700Z","2025-11-19 22:37:21.5329408Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Running 'standard' config",,,,,,,,,,,1763591841532940800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:22.337798100Z","2025-11-19 22:37:21.5331820Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before starting subprocess to inject to",,,,,,,,,,,1763591841533182000,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:21.5339696Z","2025-11-19 22:37:21.5339696Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 5604 attack-890.exe",3452,,," 7284 whoami.exe",,,"C:\Windows\System32\whoami.exe",,,,,,,,,,1763591841533969600,134080654423385232,0,160109,"0x","","",5604,6624,6628,3,0,0,1,3602411345,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:21.5373410Z","2025-11-19 22:37:21.5373410Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",3452,,," 7284 whoami.exe",,,,,,,,,,,,,1763591841537341000,,,,,,,,,,,,,,,18446633084031127552,18446633084031102976,140702344617136,0,705865940992,14048,705864925184,705864916992,140702344617136,,,,,,,,,,,,,
"2025-11-19 22:37:22.345203800Z","2025-11-19 22:37:21.5407378Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After starting subprocess with PID 7284",,,,,,,,,,,1763591841540737800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:23.308564200Z","2025-11-19 22:37:22.5236651Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before opening process handle",,,,,,,,,,,1763591842523665100,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:23.308868400Z","2025-11-19 22:37:22.5239746Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After opening process handle",,,,,,,,,,,1763591842523974600,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:24.262849900Z","2025-11-19 22:37:23.4973313Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before allocating memory for shellcode",,,,,,,,,,,1763591843497331300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:24.263130400Z","2025-11-19 22:37:23.4976143Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After allocating memory for shellcode at 00000249213E0000",,,,,,,,,,,1763591843497614300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:25.227755400Z","2025-11-19 22:37:24.4818310Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before writing shellcode to process",,,,,,,,,,,1763591844481831000,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:25.228060100Z","2025-11-19 22:37:24.4821409Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After writing shellcode to process at 00000249213E0000",,,,,,,,,,,1763591844482140900,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:26.182844300Z","2025-11-19 22:37:25.4563155Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before changing memory protection to PAGE_EXECUTE_READ",,,,,,,,,,,1763591845456315500,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:26.183142300Z","2025-11-19 22:37:25.4566185Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After changing memory protection to PAGE_EXECUTE_READ",,,,,,,,,,,1763591845456618500,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:27.147034500Z","2025-11-19 22:37:26.4400898Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before reading memory to verify write",,,,,,,,,,,1763591846440089800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:27.147308700Z","2025-11-19 22:37:26.4403653Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Before creating remote thread",,,,,,,,,,,1763591846440365300,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:26.4406187Z","2025-11-19 22:37:26.4406187Z","ETW","Microsoft-Windows-Kernel-Process",3,"ThreadStart Start "," 5604 attack-890.exe",3452,,," 7284 whoami.exe",,,,,,,,,,,,,1763591846440618700,,,,,,,,,,,,,,,18446633084031987712,18446633084031963136,2513113579520,0,705865949184,14412,705865449472,705865441280,2513113579520,,,,,,,,,,,,,
"2025-11-19 22:37:27.147575800Z","2025-11-19 22:37:26.4406370Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"After creating remote thread",,,,,,,,,,,1763591846440637000,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:26.4541760Z","2025-11-19 22:37:26.4541760Z","ETW","Microsoft-Windows-Kernel-Process",1,"ProcessStart Start "," 7284 whoami.exe",14412,,," 3812 calc.exe",,,"C:\Windows\System32\calc.exe",,,,,,,,,,1763591846454176000,134080654471607920,0,90741,"0x","","",7284,6628,6629,3,0,0,1,4001445627,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:28.099873500Z","2025-11-19 22:37:27.4122768Z","myETW","Attack-Provider",1337,"AttackTask"," 5604 attack-890.exe",,,,,,"Attack done",,,,,,,,,,,1763591847412276800,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
"2025-11-19 22:37:27.4131942Z","2025-11-19 22:37:27.4131942Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 5604 attack-890.exe",8672,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591847413194200,,,,,,,,,,,,,,,18446633084029718528,18446633084029693952,140712899206080,0,867488067584,8672,867491119104,867491106816,140712899206080,1934283,,,,,,,,,,,,
"2025-11-19 22:37:27.4131969Z","2025-11-19 22:37:27.4131969Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 5604 attack-890.exe",5960,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591847413196900,,,,,,,,,,,,,,,18446633084029747200,18446633084029722624,140712899206080,0,867488059392,5960,867490070528,867490062336,140712899206080,2523090,,,,,,,,,,,,
"2025-11-19 22:37:27.4132046Z","2025-11-19 22:37:27.4132046Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 5604 attack-890.exe",12460,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591847413204600,,,,,,,,,,,,,,,18446633084029460480,18446633084029435904,140712899206080,0,867488075776,12460,867492167680,867492155392,140712899206080,1586126,,,,,,,,,,,,
"2025-11-19 22:37:27.4133776Z","2025-11-19 22:37:27.4133776Z","ETW","Microsoft-Windows-Kernel-Process",4,"ThreadStop Stop "," 5604 attack-890.exe",3452,,," 5604 attack-890.exe",,,,,,,,,,,,,1763591847413377600,,,,,,,,,,,,,,,18446633084027822080,18446633084027797504,140695618865008,0,867488051200,3452,867486007296,867485986816,140695618865008,55165128,,,,,,,,,,,,
"2025-11-19 22:37:27.4136009Z","2025-11-19 22:37:27.4136009Z","ETW","Microsoft-Windows-Kernel-Process",2,"ProcessStop Stop "," 5604 attack-890.exe",3452,,," 5604 attack-890.exe",,,"attack-890.exe",,,,,,,,,,1763591847413600900,134080654410040405,,,,,,,,6624,,,,,,,,,,,,,,,,974848,974848,61411560,0,134080654481010332,52,9,0,0,3,48,0
"2025-11-19 22:37:28.2303954Z","2025-11-19 22:37:28.2303954Z","ETW","Microsoft-Windows-Kernel-Process",2,"ProcessStop Stop "," 7284 whoami.exe",14412,,," 7284 whoami.exe",,,"whoami.exe",,,,,,,,,,1763591848230395400,134080654423385232,,,,,,,,6628,,,,,,,,,,,,,,,,1265664,1310720,56924383,3221225477,134080654489015372,83,0,1,3,3,0,0
Can't render this file because it contains an unexpected character in line 1 and column 771.
File diff suppressed because it is too large Load Diff
Binary file not shown.