32 results found Sort:

347
4.2k
bsd-2-clause
87
C/C++ Performance Profiler
Created 2017-09-21
6,736 commits to main branch, last one 6 months ago
190
2.2k
other
70
Adversary tradecraft detection, protection, and hunting
Created 2016-03-25
999 commits to master branch, last one 4 days ago
Command line tracing tool for Windows, based on ETW.
Created 2016-09-06
111 commits to master branch, last one 9 months ago
149
605
other
40
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
Created 2016-10-24
165 commits to master branch, last one about a month ago
59
532
apache-2.0
28
A wireshark plugin to instrument ETW
Created 2020-05-29
23 commits to master branch, last one 2 years ago
Event Tracing For Windows (ETW) Resources
Created 2021-08-07
315 commits to main branch, last one about a month ago
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
Created 2021-09-25
2 commits to master branch, last one 9 days ago
My notes on software troubleshooting, covering debugging and tracing techniques and tools. Available at wtrace.net.
Created 2014-12-24
438 commits to main branch, last one 18 days ago
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Created 2021-07-08
1,247 commits to main branch, last one 7 months ago
59
267
apache-2.0
21
ETW Python Library
Created 2017-09-08
67 commits to master branch, last one about a year ago
29
250
unknown
6
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Created 2023-04-26
2 commits to main branch, last one about a year ago
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
Created 2024-08-04
93 commits to main branch, last one 17 days ago
Capture and parse CDP and LLDP packets on local or remote computers
Created 2019-04-30
79 commits to master branch, last one about a year ago
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
Created 2016-12-03
100 commits to master branch, last one 3 years ago
A small real time SyncML protocol Viewer
Created 2019-10-02
250 commits to master branch, last one 29 days ago
让Etwhook再次伟大! Make InfinityHook Great Again!
Created 2021-06-23
6 commits to main branch, last one 3 years ago
18
119
apache-2.0
1
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
Created 2022-08-15
20 commits to main branch, last one 2 years ago
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Created 2022-03-16
696 commits to main branch, last one about a month ago
Tool and library to convert ETW logs to JSON files
Created 2015-08-03
24 commits to master branch, last one 2 years ago
Two in one, patch lifetime powershell console, no more etw and amsi!
Created 2024-06-22
6 commits to main branch, last one 4 months ago
Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW
Created 2023-03-15
7 commits to main branch, last one about a year ago
Patch AMSI and ETW in remote process via direct syscall
Created 2022-02-18
3 commits to main branch, last one 2 years ago
Sampling profiler for native applications on Windows, based on ETW
Created 2018-06-10
102 commits to master branch, last one 6 months ago
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
Created 2023-02-20
9 commits to main branch, last one 8 months ago
24
65
other
11
Basically a KrabsETW rip-off written in Rust
Created 2021-04-26
198 commits to master branch, last one 4 months ago
14
64
other
11
Logs key Windows process performance metrics. #nsacyber
This repository has been archived (exclude archived)
Created 2019-05-16
37 commits to master branch, last one 3 years ago
20
59
mit
7
Go library for ETW (Event Tracing for Windows) events processing
Created 2020-05-12
57 commits to master branch, last one 3 years ago
List the ETW provider(s) in the registration table of a process.
Created 2023-08-31
3 commits to main branch, last one about a year ago
16
50
apache-2.0
10
An IDA plugin to deal with Event Tracing for Windows (ETW)
Created 2020-05-29
6 commits to master branch, last one 2 years ago
TraceLogging events and tracing
Created 2019-04-30
69 commits to main branch, last one 2 months ago