repnz / etw-providers-docs
Document ETW providers
☆223Updated 4 years ago
Alternatives and similar repositories for etw-providers-docs:
Users that are interested in etw-providers-docs are comparing it to the libraries listed below
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆289Updated 10 months ago
- View ETW Provider manifest☆465Updated 4 months ago
- Sysmon-Like research tool for ETW☆352Updated 2 years ago
- KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.☆646Updated 2 weeks ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆171Updated last year
- A collection of free miscellaneous Windows tools☆131Updated 7 months ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆269Updated 3 years ago
- Run Processes as PPL with ELAM☆157Updated 3 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆139Updated 6 years ago
- Extended Process Monitor-like tool based on Event Tracing for Windows☆468Updated 5 years ago
- Source code for File Test - Interactive File System Test Tool☆279Updated last week
- RPC Monitor tool based on Event Tracing for Windows☆341Updated 7 months ago
- Useful scripts for WinDbg using the debugger data model☆407Updated 11 months ago
- Authenticode Hash Calculator for PE32/PE32+ files☆109Updated last year
- Named pipe I/O ETW provider for Windows☆70Updated 4 years ago
- Process Monitor X v2☆603Updated last year
- Event Tracing For Windows (ETW) Resources☆365Updated 5 months ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆94Updated 2 months ago
- Extract Windows Defender database from vdm files and unpack it☆437Updated 5 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆119Updated 7 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆107Updated 4 years ago
- Toy scripts for playing with WinDbg JS API☆225Updated 8 months ago
- C++ Exceptions in Windows Drivers☆204Updated 4 years ago
- PE Viewer☆168Updated 2 months ago
- Detours with just single dependency - NTDLL☆620Updated 2 years ago
- ☆173Updated 4 years ago
- This is a repo for small, useful scripts and extensions☆244Updated last year
- Windows Filtering Platform Explorer☆249Updated 2 months ago
- Log ALPC activity☆82Updated last year
- ☆158Updated 5 months ago