27 results found Sort:

342
4.1k
bsd-2-clause
89
C/C++ Performance Profiler
Created 2017-09-21
6,736 commits to main branch, last one 2 months ago
Command line tracing tool for Windows, based on ETW.
Created 2016-09-06
111 commits to master branch, last one 5 months ago
146
575
other
39
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
Created 2016-10-24
157 commits to master branch, last one a day ago
57
521
apache-2.0
28
A wireshark plugin to instrument ETW
Created 2020-05-29
23 commits to master branch, last one 2 years ago
系统监控开发套件(sysmon、procmon、edr、终端安全、主机安全、零信任、上网行为管理、沙箱)
Created 2021-09-25
96 commits to master branch, last one 9 days ago
Event Tracing For Windows (ETW) Resources
Created 2021-08-07
311 commits to main branch, last one about a year ago
My notes on software troubleshooting, covering debugging and tracing techniques and tools. Available at wtrace.net.
Created 2014-12-24
436 commits to main branch, last one 16 days ago
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Created 2021-07-08
1,247 commits to main branch, last one 3 months ago
59
263
apache-2.0
21
ETW Python Library
Created 2017-09-08
67 commits to master branch, last one about a year ago
29
247
unknown
6
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Created 2023-04-26
2 commits to main branch, last one about a year ago
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
Created 2016-12-03
100 commits to master branch, last one 2 years ago
Capture and parse CDP and LLDP packets on local or remote computers
Created 2019-04-30
79 commits to master branch, last one about a year ago
A small real time SyncML protocol Viewer
Created 2019-10-02
248 commits to master branch, last one 7 days ago
让Etwhook再次伟大! Make InfinityHook Great Again!
Created 2021-06-23
6 commits to main branch, last one 2 years ago
19
115
apache-2.0
1
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
Created 2022-08-15
20 commits to main branch, last one about a year ago
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Created 2022-03-16
687 commits to main branch, last one 2 days ago
Tool and library to convert ETW logs to JSON files
Created 2015-08-03
24 commits to master branch, last one about a year ago
Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW
Created 2023-03-15
7 commits to main branch, last one about a year ago
Patch AMSI and ETW in remote process via direct syscall
Created 2022-02-18
3 commits to main branch, last one 2 years ago
Sampling profiler for native applications on Windows, based on ETW
Created 2018-06-10
102 commits to master branch, last one about a month ago
14
62
other
11
Logs key Windows process performance metrics. #nsacyber
This repository has been archived (exclude archived)
Created 2019-05-16
37 commits to master branch, last one 3 years ago
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
Created 2023-02-20
9 commits to main branch, last one 4 months ago
19
58
mit
7
Go library for ETW (Event Tracing for Windows) events processing
Created 2020-05-12
57 commits to master branch, last one 3 years ago
19
56
other
11
Basically a KrabsETW rip-off written in Rust
Created 2021-04-26
196 commits to master branch, last one 16 days ago
20
52
apache-2.0
10
An IDA plugin to deal with Event Tracing for Windows (ETW)
Created 2020-05-29
6 commits to master branch, last one about a year ago
ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection &...
Created 2021-05-29
92 commits to main branch, last one 2 years ago
List the ETW provider(s) in the registration table of a process.
Created 2023-08-31
3 commits to main branch, last one 9 months ago