Log sources › etw:Microsoft-Windows-Kernel-Process
etw:Microsoft-Windows-Kernel-Process
Inverted view: what can be detected if this is the log you have. Windows
12
channels
12
analytics
12
techniques
43
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
APCQueueOperations |
DC0021 OS API Execution | AN0277 | 1 |
API Calls |
DC0021 OS API Execution | AN0822 AN2029 | 2 |
API calls |
DC0021 OS API Execution | AN1399 | 1 |
API tracing / stack tracing via ETW or telemetry-based EDR |
DC0021 OS API Execution | AN0250 | 1 |
CreateTransaction, CreateFileTransacted, RollbackTransaction, NtCreateProcessEx, NtCreateThreadEx |
DC0021 OS API Execution | AN1501 | 1 |
High-frequency or suspicious sequence of QueryPerformanceCounter/GetTickCount API calls from a non-standard process lineage |
DC0021 OS API Execution | AN0430 | 1 |
Memory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser process |
DC0020 Process Modification | AN0498 | 1 |
NtQueryInformationProcess |
DC0021 OS API Execution | AN1045 | 1 |
NtUnmapViewOfSection, VirtualAllocEx, WriteProcessMemory, SetThreadContext, ResumeThread |
DC0021 OS API Execution | AN1076 | 1 |
WriteProcessMemory: WriteProcessMemory targeting regions containing KernelCallbackTable addresses |
DC0021 OS API Execution | AN1593 | 1 |
api_call: UpdateProcThreadAttribute (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS) and CreateProcess* with EXTENDED_STARTUPINFO_PRESENT / StartupInfoEx |
DC0021 OS API Execution | AN1351 | 1 |
process_start: EventHeader.ProcessId true parent vs reported PPID mismatch |
DC0034 Process Metadata | AN1351 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1027.007 Dynamic API Resolution | stealth | 0 | 0 |
| T1036.012 Browser Fingerprint | stealth | 0 | 0 |
| T1055 Process Injection | stealth, privilege escalation | 37 | 19 |
| T1055.003 Thread Execution Hijacking | stealth, privilege escalation | 2 | 0 |
| T1055.004 Asynchronous Procedure Call | stealth, privilege escalation | 0 | 0 |
| T1055.012 Process Hollowing | stealth, privilege escalation | 5 | 1 |
| T1055.013 Process Doppelgänging | stealth, privilege escalation | 0 | 0 |
| T1124 System Time Discovery | discovery | 3 | 0 |
| T1134.004 Parent PID Spoofing | stealth, privilege escalation | 1 | 0 |
| T1189 Drive-by Compromise | initial access | 3 | 21 |
| T1574.013 KernelCallbackTable | stealth, execution | 0 | 0 |
| T1622 Debugger Evasion | stealth, discovery | 1 | 2 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1622 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | T1055 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1622 | Mapped |
| CVE-2023-0386 | Linux Kernel | T1055.012 | Stale |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | T1055 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway | T1055 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1055 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1055 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | T1055 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | T1055 | Mapped |
| CVE-2024-58136 | Yiiframework Yii | T1055 | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | T1055 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1055 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1055 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1055 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1055 | Mapped |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | T1055 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1055 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1055 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1055 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1055 | Mapped |
| CVE-2025-31324 | SAP NetWeaver | T1055 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |