zodiacon / EtwExplorer
View ETW Provider manifest
☆432Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for EtwExplorer
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆268Updated 6 months ago
- Document ETW providers☆206Updated 4 years ago
- Sysmon-Like research tool for ETW☆336Updated 2 years ago
- Event Tracing For Windows (ETW) Resources☆349Updated last month
- KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.☆610Updated last week
- RPC Monitor tool based on Event Tracing for Windows☆330Updated 3 months ago
- ☆732Updated last year
- Process Monitor X v2☆589Updated 9 months ago
- Useful scripts for WinDbg using the debugger data model☆389Updated 7 months ago
- Expriments☆442Updated last month
- RpcView is a free tool to explore and decompile Microsoft RPC interfaces☆928Updated last year
- Extract Windows Defender database from vdm files and unpack it☆425Updated 4 years ago
- A collection of free miscellaneous Windows tools☆123Updated 2 months ago
- A DTrace on Windows Reimplementation☆328Updated 3 weeks ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆686Updated 8 months ago
- Exploring RPC interfaces on Windows☆284Updated 9 months ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆544Updated last year
- My personal cheat sheet for using WinDbg for kernel debugging☆387Updated last month
- Windows Registry Knowledge Base☆162Updated last month
- Enumerate and disable common sources of telemetry used by AV/EDR.☆770Updated 3 years ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆792Updated 2 years ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆160Updated 8 months ago
- Windows 10 System Programming book samples☆408Updated 5 months ago
- This is a repo for small, useful scripts and extensions☆240Updated last year
- PE Viewer☆152Updated 3 weeks ago
- Windows registry file format specification☆325Updated 6 years ago
- Windows Filtering Platform Explorer☆211Updated last month
- awesome windbg extensions☆313Updated 5 years ago
- Samples for the book Windows Kernel Programming, 2nd edition☆293Updated 3 months ago
- The Windows Kernel Programming book samples☆611Updated last year