microsoft / ebpf-for-windows-demoLinks
This repository contains the demo material built on top of ebpf-for-windows platform.
☆43Updated 8 months ago
Alternatives and similar repositories for ebpf-for-windows-demo
Users that are interested in ebpf-for-windows-demo are comparing it to the libraries listed below
Sorting:
- Simple example for getting started with eBPF for Windows☆44Updated 3 months ago
- ☆83Updated 2 weeks ago
- eBPF-For-Windows extension to provide access to Windows kernel functionality☆26Updated last week
- WinDbg installer/updater☆41Updated last year
- The Linux port of the Sysinternals Sysmon tool.☆262Updated 2 months ago
- Tooling to generate metadata for Win32 APIs in the Windows Driver Kit (WDK).☆101Updated 3 months ago
- Red Canary's eBPF Sensor☆107Updated 2 weeks ago
- A WinDbg extension to trace COM interactions☆114Updated last year
- A mini filter driver development framework allows you to develop minit filter driver with different features.☆48Updated last month
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆63Updated 4 months ago
- Trace events in real time sessions☆45Updated last year
- TraceLogging events and tracing☆53Updated 2 weeks ago
- OpenHCL Linux Kernel☆14Updated last week
- anti-ransomware file-system filter☆59Updated 8 months ago
- Security testing tools for Windows sandboxing technologies☆169Updated 3 weeks ago
- Tool and library to convert ETW logs to JSON files☆89Updated 2 years ago
- Windows Monitoring Agent (process creation + DLL loading monitor + network monitor + file system access monitor + etc)☆61Updated 6 years ago
- VM firmware pkg for Project Mu☆41Updated this week
- C/C++ libraries for working with Linux Tracepoints and user_events☆43Updated 2 months ago
- Sample code demonstrating use cases of the Microsoft.Windows.EventTracing.Processing.All nuget package.☆45Updated last year
- This is the Linux kernel module event collector for the Carbon Black Cloud.☆18Updated last year
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- ☆61Updated last year
- INF Studio for easier working with driver installation files☆38Updated last year
- Utility functions for building Windows kernel drivers in Rust☆21Updated 3 years ago
- A C DLL that can control powershell☆45Updated 5 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- The TpmTool utility is a simple cross-platform tool for accessing TPM2.0 Non-Volatile (NV) Spaces (Index Values) on compliant systems, wi…☆144Updated 3 years ago
- Show Window Stations, Desktops and top level windows☆15Updated last year
- Elastic's eBPF☆68Updated last month