etw forensics

  1. Hidden Windows Telemetry Artifacts: AutoLogger DiagTrack ETL for Forensics

    FortiGuard Labs has revealed that a little‑known Windows telemetry file — AutoLogger‑Diagtrack‑Listener.etl — can contain usable forensic traces of process execution, including evidence of deleted malware and attacker activity, offering incident responders an unexpected secondary source of truth...