WithSecure documented how Windows AV and EDR drivers collect inline telemetry through kernel callbacks for process, thread, and object-access activity, including user-mode call stacks. Sysmon, for example, uses an object-handle callback and RtlWalkFrameChain to populate the CallTrace field in Event ID 10 process-access records; such traces can expose direct system calls by showing execution paths that omit ntdll before the kernel service transition. The research showed that x64 unwind metadata and frame reconstruction determine what collectors record, raising the prospect that an attacker could forge a plausible stack to mislead callback-based detections. Windows Security Event ID 4688 remains a separate audit source for newly created processes.
Elastic Security Labs reported that kernel-originated ETW is generally more resistant to user-mode tampering than telemetry produced by user-mode clients or services, but warned that trusted event origin does not ensure complete or accurate data. Its analysis found that many kernel ETW events—particularly opaque or legacy providers—require manifests, symbols, binary analysis, or reverse engineering to interpret, and that some events record only failures. Organizations should correlate process-creation auditing, Sysmon call traces, and kernel ETW rather than rely on any one source, and validate whether their detections account for missing, manipulated, or semantically limited stack and ETW data.

See real exploitation activity before you spend the cycle.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcelabs.withsecure.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.