etw
Here are 20 public repositories matching this topic...
Shitty C++20 single-header ETW util for real-time event consumption and member parsing
-
Updated
Oct 26, 2025 - C++
System Activity Monitor (SAM) is a research tool that enables detailed recording of system and application behavior and resource usage.
-
Updated
Sep 8, 2022 - C++
Greathelm is a modular Windows security service focused on process inspection, PowerShell telemetry, and automated response enforcement. It’s built entirely in C++ and designed for minimal dependencies, direct API usage.
-
Updated
Nov 2, 2025 - C++
Bypassing Event Tracing for Windows (ETW) with CSharp
-
Updated
Jul 20, 2023 - C++
A simple example application to collect DNS queries logs using etw-api
-
Updated
May 11, 2020 - C++
Open Power Performance Analysis Tool
-
Updated
Sep 10, 2022 - C++
Mentally ill EtwTi parser
-
Updated
Oct 13, 2025 - C++
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
-
Updated
Feb 11, 2024 - C++
Simple project that demonstrates how an ETW consumer can be created just by using NTDLL
-
Updated
Feb 23, 2019 - C++
Hades HIDS/HIPS for Windows
-
Updated
Oct 10, 2025 - C++
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
-
Updated
Feb 19, 2025 - C++
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
-
Updated
Mar 10, 2025 - C++
C/C++ Performance Profiler
-
Updated
Jan 31, 2025 - C++
Improve this page
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."