Repository navigation

#

etw

Adversary tradecraft detection, protection, and hunting

Go
2319
4 天前
xoofx/ultra

An advanced profiler for .NET Applications on Windows

C#
1029
4 个月前

Command line tracing tool for Windows, based on ETW.

C#
679
1 年前

KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.

C++
650
1 个月前

A wireshark plugin to instrument ETW

Lua
555
3 年前

Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.

C#
377
14 天前

Event Tracing For Windows (ETW) Resources

Python
375
7 个月前

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发

C++
352
2 个月前

My notes on software troubleshooting, covering debugging and tracing techniques and tools. Available at wtrace.net.

HTML
333
3 个月前

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

C#
301
1 年前

ETW Python Library

Python
281
2 年前

C# POC to extract NetNTLMv1/v2 hashes from ETW provider

C#
253
2 年前

Document ETW providers

C
228
5 年前

Capture and parse CDP and LLDP packets on local or remote computers

PowerShell
176
2 年前

A small real time SyncML protocol Viewer

C#
175
3 个月前

Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool

C#
162
2 年前
C#
157
1 个月前

Simple project that demonstrates how an ETW consumer can be created just by using NTDLL

C++
140
6 年前