#
etw
Here are 11 public repositories matching this topic...
A proof of concept ETW consumer that captures userland events in real time, displays them, and saves them into an .etl file
-
Updated
Mar 2, 2025 - C
A demo of the relevant blog post: Introduction to Beacon Object Files
-
Updated
Mar 26, 2023 - C
Trace ScriptBlock execution for powershell v2
-
Updated
Jan 14, 2020 - C
List the ETW provider(s) in the registration table of a process.
-
Updated
Sep 20, 2023 - C
Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW
-
Updated
Mar 19, 2023 - C
Improve this page
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."