asgarciap / etw-dnsView external linksLinks
A simple example application to collect DNS queries logs using etw-api
☆27May 11, 2020Updated 5 years ago
Alternatives and similar repositories for etw-dns
Users that are interested in etw-dns are comparing it to the libraries listed below
Sorting:
- 冰云安全U盘☆17Oct 3, 2022Updated 3 years ago
- Brand New Code Injection for Windows https://breakingmalware.com/injection-techniques/atombombing-brand-new-code-injection-for-windows☆18Oct 29, 2016Updated 9 years ago
- copy of tdifw lib☆10Jun 15, 2017Updated 8 years ago
- DTrace for Windows in userspace; Frontend to ETW☆27Oct 4, 2022Updated 3 years ago
- Visual Studio Extension and tools to ease development using Event Tracing for Windows (ETW).☆14Oct 6, 2020Updated 5 years ago
- iSwordSDK (Provide Powerful Kernel API For Ring3 Applications)☆15Mar 25, 2022Updated 3 years ago
- A simple parser(library) which extracts shimcache data from windows.☆15May 20, 2019Updated 6 years ago
- WFP驱动,关联链路层和进程信息☆16Oct 17, 2021Updated 4 years ago
- windows net program☆13Oct 16, 2014Updated 11 years ago
- Popular driver source with guarded regions bypass☆15Nov 12, 2022Updated 3 years ago
- Repository containing malware analysis filters for the Windows SysInternals' - Process Monitor tool☆20Oct 2, 2020Updated 5 years ago
- Disable any USB Mass Storage device from kmode using a pnp filter driver☆65Jan 24, 2021Updated 5 years ago
- Windows system repair tool☆18Jun 2, 2021Updated 4 years ago
- Event Tracing for Windows Custom Events☆21Jan 28, 2015Updated 11 years ago
- ☆18Sep 27, 2016Updated 9 years ago
- 一个可以帮助你进行Windows驱动开发和分析的工具。☆46Jun 13, 2021Updated 4 years ago
- The project hooks windows printer functions using the Deviare Interception Engine☆18Jun 6, 2012Updated 13 years ago
- Basics of Reverse Engineering Winter 2022☆28Mar 11, 2022Updated 3 years ago
- 粗暴地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆27Jan 14, 2018Updated 8 years ago
- BYOVD collection☆24Mar 20, 2024Updated last year
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 6 years ago
- An minifilter-based transparent encryptor☆43May 21, 2014Updated 11 years ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Mar 22, 2020Updated 5 years ago
- 让Etwhook再次伟大! Make InfinityHook Great Again!☆147Jun 24, 2021Updated 4 years ago
- ☆174Sep 9, 2020Updated 5 years ago
- Extract data of TTD trace file to a minidump☆31Jul 31, 2023Updated 2 years ago
- View ETW Provider manifest☆570Nov 1, 2024Updated last year
- A POC for Windows Extension Host hooking☆24Jul 13, 2019Updated 6 years ago
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆329May 2, 2024Updated last year
- Process Monitor X v2☆648Jan 22, 2024Updated 2 years ago
- Various WinDbg extensions and scripts☆32Sep 13, 2018Updated 7 years ago
- A ProcMon-esque tool for monitoring Windows Kernel Drivers☆62May 31, 2021Updated 4 years ago
- ☆69Mar 3, 2022Updated 3 years ago
- Reverse engineering toolkit for exploit/malware analysis☆35May 10, 2020Updated 5 years ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆132May 17, 2023Updated 2 years ago
- ☆48Nov 7, 2018Updated 7 years ago
- Debug Print viewer (user and kernel)☆71Feb 7, 2024Updated 2 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆298Apr 10, 2021Updated 4 years ago
- Sysmon shenanigans☆66Oct 9, 2020Updated 5 years ago