C/C++ Performance Profiler
-
Updated
Jan 31, 2025 - C++
C/C++ Performance Profiler
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
Hades HIDS/HIPS for Windows
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
Simple project that demonstrates how an ETW consumer can be created just by using NTDLL
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
A simple example application to collect DNS queries logs using etw-api
Open Power Performance Analysis Tool
Mentally ill EtwTi parser
System Activity Monitor (SAM) is a research tool that enables detailed recording of system and application behavior and resource usage.
Bypassing Event Tracing for Windows (ETW) with CSharp
Shitty C++20 single-header ETW util for real-time event consumption and member parsing
Greathelm is a modular Windows security service focused on process inspection, PowerShell telemetry, and automated response enforcement. It’s built entirely in C++ and designed for minimal dependencies, direct API usage.
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."