The Windows Atomic lab corpus records the expected changes, but several ETW event families lose process fields in the recorded payload. This limits process-scoped correlation and replay even when event content is present.
Evidence from a disposable Windows 11 lab, Rustinel 1.8.0 at 8c6ac3f88c5ad3c4d607e31cb3f35ce848f2a834, upstream Atomic revision 388942adbd9641f4dfdcf079d7efe9a75ec0ac43:
- The 80-test discovery batch matched all 3,259 native PowerShell 4103 records and 745 native 4104 records attributed to the test process trees. The matching Rustinel payloads lack structured actor fields.
- Across the latest 52 mutation tests, all 45 registry-write behavior checks and six file create/delete checks found the expected target records, but their recorded fields omitted
ProcessId while retaining Image.
- Four receiver-confirmed synthetic TXT queries produced four DNS 3006 starts and four 3008 successful completions, all missing structured
ProcessId while retaining Image.
- DLL loads have
ProcessId and ImageLoaded but often omit the host Image.
- Capture manifests were complete, checksum-valid, and reported zero source/transport loss. That validates recording integrity, not complete behavioral coverage.
Example reproductions: registry Run atomic e55be3fd-3521-4610-9d1a-e210e42dcf05; ADS creation atomic 17e7637a-ddaf-4a82-8622-377e20de8fdb; direct PowerShell atomics in the discovery corpus.
Relevant implementation:
src/sensor/windows/etw/decode.rs: PowerShell and registry decoders resolve an internal PID using payload fields or an event-header fallback, but leave the optional serialized ProcessId absent.
- Kernel file events already resolve their actor through the thread cache. Preserve that resolved actor rather than blindly using the emitting event header.
src/normalizer/mod.rs: image-load and PowerShell normalization omit the existing identity-aware image enrichment used by other families.
Acceptance:
- Preserve a provider-validated actor PID in existing event fields and use identity-safe executable enrichment where the source permits it.
- Keep emitter identity distinct from actor identity. Task Scheduler 106 comes from its service; Security 4698 already exposes the actual
ClientProcessId and ClientProcessStartKey and was correctly captured in this campaign.
- Verify raw capture and replay with native-source fixtures and PID-reuse cases. Do not fabricate attribution when the source cannot establish it.
Related: #417, #394, #641, #658. The private corpus contains host telemetry and is not attached publicly.
Test coverage note (2026-09-30)
The fixtures recorded from real events proposed in #641 are the natural regression tests for this fix, and #671's corpus can supply them.
This issue does not wait on #641.
The Windows Atomic lab corpus records the expected changes, but several ETW event families lose process fields in the recorded payload. This limits process-scoped correlation and replay even when event content is present.
Evidence from a disposable Windows 11 lab, Rustinel 1.8.0 at
8c6ac3f88c5ad3c4d607e31cb3f35ce848f2a834, upstream Atomic revision388942adbd9641f4dfdcf079d7efe9a75ec0ac43:ProcessIdwhile retainingImage.ProcessIdwhile retainingImage.ProcessIdandImageLoadedbut often omit the hostImage.Example reproductions: registry Run atomic
e55be3fd-3521-4610-9d1a-e210e42dcf05; ADS creation atomic17e7637a-ddaf-4a82-8622-377e20de8fdb; direct PowerShell atomics in the discovery corpus.Relevant implementation:
src/sensor/windows/etw/decode.rs: PowerShell and registry decoders resolve an internal PID using payload fields or an event-header fallback, but leave the optional serializedProcessIdabsent.src/normalizer/mod.rs: image-load and PowerShell normalization omit the existing identity-aware image enrichment used by other families.Acceptance:
ClientProcessIdandClientProcessStartKeyand was correctly captured in this campaign.Related: #417, #394, #641, #658. The private corpus contains host telemetry and is not attached publicly.
Test coverage note (2026-09-30)
The fixtures recorded from real events proposed in #641 are the natural regression tests for this fix, and #671's corpus can supply them.
This issue does not wait on #641.