Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet) @BlackHatOfficialYT
Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)  @BlackHatOfficialYT
Uploaded August 2026 | Updated September 2026, 3 weeks ago
Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into what's happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.

This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].

However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETW's full potential.

To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.

Asuka Nakajima | Senior Security Research Engineer, Elastic

blackhat.com/asia-26/briefings/schedule/?#hidden-telemetry-uncovering-tracelogging-etw-providers-youre-not-using-yet-51991
Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply ChainBlack Hat Asia 2026 | IDEsaster 2.0: Another Novel Vulnerability Class in AI IDEsOperation PoisonedApple: Tracing Credit Card Information Theft to Payment FraudBlack Hat Vault | Cyber GrannyInternal Server Error: Exploiting Inter-Process Communication in SAPs HTTP ServerSecTor 2025 | Threat Architecture, Attack Surfaces & Real-World RiskSecTor 2025 | Unmasking a North Korean IT FarmBlack Hat Asia 2026 | Remote Server, Local Root. Welcome to MCP.Black Hat USA 2025 | Watch Your (Lock)Step: Glitching into Automotive ProcessorsWhy leaders in cybersecurity keep coming back to Black HatBlack Hat USA 2026 | Reverse Engineering GCD, XPC Races, and macOS Detection
Black Hat |

Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers You're Not Using (Yet)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER