Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into what's happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.
This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].
However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETW's full potential.
To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.
Asuka Nakajima | Senior Security Research Engineer, Elastic
https://ift.tt/PNbRd1M
source https://www.youtube.com/watch?v=ubFcs1M62P4
The Cyber Stream
Latest News for Cyber Security & Technology
Friday, 14 August 2026
Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply Chain
Cloud images are frequently stale on arrival. Traditional hardening depends on manual patch cycles and periodic rebuilds—an approach that breaks down in large enterprises running thousands of rapidly changing workloads. Reactive remediation creates persistent security debt, long exposure windows, and an image supply chain that cannot keep pace with modern Agile delivery.
This Briefing presents a security-first framework for a self-healing image supply chain that continuously delivers deterministic, verifiable, and zero-CVE operating system images at enterprise scale. The approach replaces legacy package-manager–driven workflows with hermetic, declarative builds that remove non-determinism and guarantee 100% reproducibility. Every image is cryptographically signed, attested with SLSA-aligned provenance, and verified prior to promotion, preventing compromised or untrusted components from reaching production.
Our platform implements this framework, with layered hardening and minimal-footprint custom builds that eliminate unnecessary utilities, reducing attack surface while preserving developer flexibility. Strict policy gates ensure that only images meeting integrity, compliance, and vulnerability criteria are deployable.
To sustain security posture at scale, the system continuously tracks vulnerability intelligence feeds and upstream base-layer updates. When a patch or new CVE is released, images are automatically regenerated, validated, and published—guaranteeing updated images in less than 24 hours without manual intervention.
In production use, the framework is actively consumed by 500+ SREs impacting 1000s of developers across 70+ engineering teams, has reduced organization-wide CVE backlog by approximately 40%, and scales to support thousands of workloads. Today it supports hardened Linux and Windows OS images across AWS and Azure, with a design extensible to data-center images and container pipelines.
We will share the architecture framework, threat model and implementation techniques as a vendor-neutral blueprint so security and platform teams can transform image security from a reactive process into an autonomous, continuously verified supply chain.
Neelu Tripathy | Senior Security Architect, Adobe Inc.
Lovlesh Malik | Engineering Manager, Adobe Systems India Pvt. Ltd
https://ift.tt/7OeFs2o
source https://www.youtube.com/watch?v=ueG0ynK0I7A
source https://www.youtube.com/watch?v=ueG0ynK0I7A
Thursday, 13 August 2026
Black Hat Asia 2026 | Inside Cybercrime Inc: Lessons From Covering the Global Fraud Boom
Drawing on three years of on the ground reporting across South East Asia, this talk examines the rise of an industrial scale cybercrime economy, an ecosystem now generating an estimated $500bn a year, rivaling the global drug trade. I'll unpack how these syndicates operate as fully fledged multinational enterprises, and explore the human, political and economic forces that allow them to thrive. By tracing how online fraud has evolved, industrialised and globalised, I'll outline what this transformation reveals about the future of organised crime and why defenders, policymakers and investigators need to rethink the threat landscape ahead.
Sue-Lin Wong | Asia Correspondent, The Economist
https://ift.tt/xcOnhQI
source https://www.youtube.com/watch?v=ChQ-wvvgGNU
source https://www.youtube.com/watch?v=ChQ-wvvgGNU
Black Hat Vault | Cyber Granny
Meet Cyber Granny! 🔐 Hear her thoughts on the Black Hat community, advice for newcomers, and the importance of staying cyber aware.
source https://www.youtube.com/shorts/vgyZ7AaAZCM
source https://www.youtube.com/shorts/vgyZ7AaAZCM
Black Hat Stories | Daniel Cuthbert
From world-class research to the collaborative spirit that brings the global security community together, Daniel shares how Black Hat has helped shape some of the most important moments in cybersecurity history.
source https://www.youtube.com/shorts/GiWY0pNKH_4
source https://www.youtube.com/shorts/GiWY0pNKH_4
Wednesday, 12 August 2026
Black Hat Stories | More Than a Conference
Three years, three different Black Hat experiences. Gaurav Keerthi, CEO and founder of StrongKeep, shares what makes it special.
source https://www.youtube.com/shorts/5Qq_L_qp7R8
source https://www.youtube.com/shorts/5Qq_L_qp7R8
Three Decades of Influence | Why Black Hat Matters
As Black Hat approaches its 30th anniversary, Daniel Cuthbert reflects on why this conference remains essential to the cybersecurity community. See how Black Hat has influenced the industry through groundbreaking research, innovation, and collaboration.
source https://www.youtube.com/shorts/tq6lYc3jZDo
source https://www.youtube.com/shorts/tq6lYc3jZDo
Tuesday, 11 August 2026
Black Hat Stories | Gaurav Keerthi, CEO and founder of StrongKeep
Passion. Knowledge. Connection. That's what keeps security professionals coming back to Black Hat year after year.
source https://www.youtube.com/shorts/OrI1Nzz9FE0
source https://www.youtube.com/shorts/OrI1Nzz9FE0
Saturday, 8 August 2026
Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius
Prompt injection is usually treated as a text problem contained on a screen: a bad output, leaked data, a rogue tool call. This one isn't. A live jailbreak of a stock Unitree Go2 robot dog running Gemini Robotics-ER 1.6, reached through its own camera and mic and driven to physical movement, no human in the loop. Underneath the demo is a measurement problem: agents behave differently when they know they're being tested, so a clean evaluation score doesn't mean the unsafe behavior is gone. The talk covers the attack live, a taxonomy of how these systems fail, why current testing misses it, and what defenders should change. Live hardware, on stage.
Pliny the Liberator | Directs Frontier-Model Research, BT6
Philip (injx) Dursey | Managing Director, BT6
Adrian (threlfall) Wood | Frontier AI Red Team Operator, BT6
Ads (0xmoose) Dawson | Senior Frontier AI Red Team Operator, BT6
Dustin (ph1r3574r73r) Farley | Frontier AI Red Team Operator, BT6
Sean (seahop) Hopkins | Frontier AI Red Team Operator, BT6
Learn more: https://ift.tt/3D6MJTn
source https://www.youtube.com/watch?v=LZkdihOzfe4
source https://www.youtube.com/watch?v=LZkdihOzfe4
Thursday, 6 August 2026
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI
When AI Goes Rogue. The Incident That Changed Everything. An OpenAI evaluation agent broke out of its sandbox, infiltrated Hugging Face infrastructure, and attempted to steal test answers—all autonomously. No human involved. The era of AI-driven cyberattacks is here. Are you prepared?
Speaker: Michael Dalton, Speaker: Eric Wallace
Learn more: https://ift.tt/La7IhuT
source https://www.youtube.com/watch?v=87DyyMV0kCY
source https://www.youtube.com/watch?v=87DyyMV0kCY
Friday, 31 July 2026
Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member
In this episode, Black Hat Training Review Board member Daniel Cuthbert discusses why Black Hat remains a driving force in the cybersecurity industry. From world-class research to the collaborative spirit that brings the global security community together, Daniel shares how Black Hat has helped shape some of the most important moments in cybersecurity history.
Discover what makes Black Hat a trusted platform for groundbreaking research, meaningful connections, and the exchange of ideas that continue to advance the industry.
🔐About Daniel Cuthbert
Global Head of Security Research | Banco Santander
Daniel Cuthbert is the Global Head of Security Research for Banco Santander. With a career spanning over 20 years on both the offensive and defensive side, he's seen the evolution of hacking from a small groups of curious minds to organized criminal networks and nation state we see today. He is the original co-author of the OWASP Testing Guide, released in 2003 and now the co-author of the OWASP Application Security Verification Standard (ASVS).
https://ift.tt/lIkNESX
source https://www.youtube.com/watch?v=e_8rik9NT7U
source https://www.youtube.com/watch?v=e_8rik9NT7U
Subscribe to:
Posts (Atom)
-
WeChat, with over 1.2 billion monthly active users, stands as the most popular messaging and social media platform in China and third global...
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...