The Payload Podcast 006

John Hammond
John HammondMay 15, 2026

Why It Matters

Understanding ETW equips defenders with deep, low‑overhead visibility while revealing a powerful avenue attackers can exploit, making it a critical focus for any Windows security strategy.

Key Takeaways

  • ETW provides low‑overhead, kernel‑level telemetry across Windows systems.
  • Researchers can use ETW for both defensive monitoring and offensive C2.
  • New tool “ETW Inspector” simplifies provider enumeration and remote trace sessions.
  • ETW data underpins Windows Event Viewer logs, exposing rich security events.
  • Remote consumption via PLA enables agent‑less data collection on target machines.

Summary

The Payload Podcast episode 006 dives deep into Event Tracing for Windows (ETW), a native Windows telemetry framework that captures granular system activity with minimal performance impact. Hosts Johnny and John discuss their recent research, announce the release of an open‑source utility called ETW Inspector, and explore how ETW powers the Windows Event Viewer while offering far richer data than most administrators realize.

They explain ETW’s architecture: providers emit events, consumers subscribe via trace sessions stored in memory, and the mechanism operates inline, avoiding the overhead of traditional function hooking. This efficiency makes ETW attractive for both defensive use—feeding endpoint detection and response (EDR) pipelines—and offensive tactics, such as stealthy command‑and‑control channels or remote data harvesting via the Performance Log Analytics (PLA) interface.

John highlights concrete examples: using PLA to create remote trace sessions without installing a disk‑based agent, and leveraging the tool to enumerate providers, capture NTFS and security‑audit events, and even patch ETW to suppress logging. He also credits James Forshaw’s “in‑object‑manager” PowerShell module as inspiration for building a PowerShell‑friendly ETW Inspector that mirrors the flexibility of Forshaw’s toolset.

The discussion underscores that ETW is a double‑edged sword. Security teams can gain unprecedented visibility into every system call, registry change, or file operation, dramatically improving detection and forensic capabilities. Conversely, threat actors can weaponize the same interface for covert monitoring and data exfiltration, making awareness and proper configuration of ETW providers essential for modern Windows security.

Original Description

Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training
See what else I'm up to with: https://jh.live/newsletter
ℹ️ Resources:
See what cybersecurity events are happening: https://jh.live/infosecmap
Learn how to code with CodeCrafters: https://jh.live/codecrafters
Host your own VPN with OpenVPN: https://jh.live/openvpn
Get Blue Team Training and SOC Analyst Certifications with CyberDefenders: https://jh.live/cyberdefense

Comments

Want to join the conversation?

Loading comments...