33 results found Sort:

349
4.2k
bsd-2-clause
87
C/C++ Performance Profiler
Created 2017-09-21
6,737 commits to main branch, last one 25 days ago
194
2.2k
other
70
Adversary tradecraft detection, protection, and hunting
Created 2016-03-25
1,039 commits to master branch, last one a day ago
9
917
bsd-2-clause
7
An advanced profiler for .NET Applications on Windows
Created 2024-11-18
32 commits to main branch, last one 20 days ago
Command line tracing tool for Windows, based on ETW.
Created 2016-09-06
111 commits to master branch, last one 11 months ago
154
614
other
40
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
Created 2016-10-24
171 commits to master branch, last one about a month ago
59
538
apache-2.0
28
A wireshark plugin to instrument ETW
Created 2020-05-29
23 commits to master branch, last one 2 years ago
Event Tracing For Windows (ETW) Resources
Created 2021-08-07
315 commits to main branch, last one 2 months ago
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
Created 2021-09-25
2 commits to master branch, last one about a month ago
My notes on software troubleshooting, covering debugging and tracing techniques and tools. Available at wtrace.net.
Created 2014-12-24
442 commits to main branch, last one 2 days ago
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Created 2021-07-08
1,247 commits to main branch, last one 9 months ago
58
272
apache-2.0
21
ETW Python Library
Created 2017-09-08
67 commits to master branch, last one about a year ago
29
251
unknown
6
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Created 2023-04-26
2 commits to main branch, last one about a year ago
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
Created 2024-08-04
107 commits to main branch, last one 14 days ago
Capture and parse CDP and LLDP packets on local or remote computers
Created 2019-04-30
79 commits to master branch, last one about a year ago
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
Created 2016-12-03
100 commits to master branch, last one 3 years ago
A small real time SyncML protocol Viewer
Created 2019-10-02
268 commits to master branch, last one 5 days ago
让Etwhook再次伟大! Make InfinityHook Great Again!
Created 2021-06-23
6 commits to main branch, last one 3 years ago
18
120
apache-2.0
1
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
Created 2022-08-15
20 commits to main branch, last one 2 years ago
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Created 2022-03-16
699 commits to main branch, last one 18 days ago
Tool and library to convert ETW logs to JSON files
Created 2015-08-03
24 commits to master branch, last one 2 years ago
Two in one, patch lifetime powershell console, no more etw and amsi!
Created 2024-06-22
6 commits to main branch, last one 5 months ago
Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW
Created 2023-03-15
7 commits to main branch, last one about a year ago
Patch AMSI and ETW in remote process via direct syscall
Created 2022-02-18
3 commits to main branch, last one 2 years ago
Sampling profiler for native applications on Windows, based on ETW
Created 2018-06-10
102 commits to master branch, last one 7 months ago
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
Created 2023-02-20
9 commits to main branch, last one 10 months ago
14
66
other
11
Logs key Windows process performance metrics. #nsacyber
This repository has been archived (exclude archived)
Created 2019-05-16
37 commits to master branch, last one 3 years ago
24
65
other
11
Basically a KrabsETW rip-off written in Rust
Created 2021-04-26
198 commits to master branch, last one 5 months ago
20
61
mit
7
Go library for ETW (Event Tracing for Windows) events processing
Created 2020-05-12
57 commits to master branch, last one 3 years ago
List the ETW provider(s) in the registration table of a process.
Created 2023-08-31
3 commits to main branch, last one about a year ago
16
50
apache-2.0
10
An IDA plugin to deal with Event Tracing for Windows (ETW)
Created 2020-05-29
6 commits to master branch, last one 2 years ago