Event Tracing for Windows EDR bypass in Rust (usermode)
-
Updated
Jun 9, 2024 - Rust
Event Tracing for Windows EDR bypass in Rust (usermode)
Monitor windows kernel event, based on etw, development in rust. A replacement of procmon. more events and useful filter. Typically can check handle leak for a few weeks.
TraceLogging events and tracing
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."