Uploaded May 2026 | Updated September 2026, 3 weeks ago
In 2022, the Canadian federal government banned the use of technologies from ZTE and Huawei in Canadian telecommunications networks, citing national security reasons. Bans on other manufacturers, such as Hikvision, are also under consideration. Technologies from these vendors may not be purchased, and existing installed devices must be removed.
However, many of these devices are "white labeled": sold under a different name, by a local vendor...but peel back the label and the forbidden device remains. The same goes for too-good-to-be-true prices for equipment on auction sites: counterfeit copies of name-brand devices are not rare.
This talk will discuss techniques to detect these devices, including Internet-wide statistical methods, and deep dives into telltale network protocol quirks. Learn how to tell if your expensive router (bought cheap!) really is the real thing, and whether your network really is free from forbidden devices.
By: Rob King | Director of Applied Security Research, runZero, Inc
blackhat.com/sector/2025/briefings/schedule/index.html#pay-no-attention-to-the-device-behind-the-curtain-detecting-forbidden-white-labeled-and-counterfeit-devices-47726
In 2022, the Canadian federal government banned the use of technologies from ZTE and Huawei in Canadian telecommunications networks, citing national security reasons. Bans on other manufacturers, such as Hikvision, are also under consideration. Technologies from these vendors may not be purchased, and existing installed devices must be removed.
However, many of these devices are "white labeled": sold under a different name, by a local vendor...but peel back the label and the forbidden device remains. The same goes for too-good-to-be-true prices for equipment on auction sites: counterfeit copies of name-brand devices are not rare.
This talk will discuss techniques to detect these devices, including Internet-wide statistical methods, and deep dives into telltale network protocol quirks. Learn how to tell if your expensive router (bought cheap!) really is the real thing, and whether your network really is free from forbidden devices.
By: Rob King | Director of Applied Security Research, runZero, Inc
blackhat.com/sector/2025/briefings/schedule/index.html#pay-no-attention-to-the-device-behind-the-curtain-detecting-forbidden-white-labeled-and-counterfeit-devices-47726








![Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)
Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into whats happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.
This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].
However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETWs full potential.
To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.
Asuka Nakajima | Senior Security Research Engineer, Elastic
https://blackhat.com/asia-26/briefings/schedule/?#hidden-telemetry-uncovering-tracelogging-etw-providers-youre-not-using-yet-51991 Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)](https://i.ytimg.com/vi/ubFcs1M62P4/mqdefault.jpg)

