Skip to content

fix(windows-etw): preserve actor PID and executable context in captures #668

Description

@Karib0u

The Windows Atomic lab corpus records the expected changes, but several ETW event families lose process fields in the recorded payload. This limits process-scoped correlation and replay even when event content is present.

Evidence from a disposable Windows 11 lab, Rustinel 1.8.0 at 8c6ac3f88c5ad3c4d607e31cb3f35ce848f2a834, upstream Atomic revision 388942adbd9641f4dfdcf079d7efe9a75ec0ac43:

  • The 80-test discovery batch matched all 3,259 native PowerShell 4103 records and 745 native 4104 records attributed to the test process trees. The matching Rustinel payloads lack structured actor fields.
  • Across the latest 52 mutation tests, all 45 registry-write behavior checks and six file create/delete checks found the expected target records, but their recorded fields omitted ProcessId while retaining Image.
  • Four receiver-confirmed synthetic TXT queries produced four DNS 3006 starts and four 3008 successful completions, all missing structured ProcessId while retaining Image.
  • DLL loads have ProcessId and ImageLoaded but often omit the host Image.
  • Capture manifests were complete, checksum-valid, and reported zero source/transport loss. That validates recording integrity, not complete behavioral coverage.

Example reproductions: registry Run atomic e55be3fd-3521-4610-9d1a-e210e42dcf05; ADS creation atomic 17e7637a-ddaf-4a82-8622-377e20de8fdb; direct PowerShell atomics in the discovery corpus.

Relevant implementation:

  • src/sensor/windows/etw/decode.rs: PowerShell and registry decoders resolve an internal PID using payload fields or an event-header fallback, but leave the optional serialized ProcessId absent.
  • Kernel file events already resolve their actor through the thread cache. Preserve that resolved actor rather than blindly using the emitting event header.
  • src/normalizer/mod.rs: image-load and PowerShell normalization omit the existing identity-aware image enrichment used by other families.

Acceptance:

  • Preserve a provider-validated actor PID in existing event fields and use identity-safe executable enrichment where the source permits it.
  • Keep emitter identity distinct from actor identity. Task Scheduler 106 comes from its service; Security 4698 already exposes the actual ClientProcessId and ClientProcessStartKey and was correctly captured in this campaign.
  • Verify raw capture and replay with native-source fixtures and PID-reuse cases. Do not fabricate attribution when the source cannot establish it.

Related: #417, #394, #641, #658. The private corpus contains host telemetry and is not attached publicly.

Test coverage note (2026-09-30)

The fixtures recorded from real events proposed in #641 are the natural regression tests for this fix, and #671's corpus can supply them.
This issue does not wait on #641.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsensorSensor and telemetry workwindowsWindows support

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions