Event Log Tampering Part 1: Disrupting the EventLog Service

You Can’t See Me

Disrupting the EventLog Service

Service Host Thread Tampering

A time gap in logs from where I started Phant0m and restarted the service.

Patching the Event Service

Downgrading Windows Components

reg add “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MiniNt”

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store