etw
Here are 105 public repositories matching this topic...
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
-
Updated
Nov 6, 2025 - C#
Greathelm is a modular Windows security service focused on process inspection, PowerShell telemetry, and automated response enforcement. It’s built entirely in C++ and designed for minimal dependencies, direct API usage.
-
Updated
Nov 2, 2025 - C++
Shitty C++20 single-header ETW util for real-time event consumption and member parsing
-
Updated
Oct 26, 2025 - C++
Monitor windows kernel event, based on etw, development in rust. A replacement of procmon. more events and useful filter. Typically can check handle leak for a few weeks.
-
Updated
Oct 22, 2025 - Rust
Command line tracing tool for Windows, based on ETW.
-
Updated
Oct 15, 2025 - C#
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
-
Updated
Nov 12, 2025 - C#
Mentally ill EtwTi parser
-
Updated
Oct 13, 2025 - C++
Hades HIDS/HIPS for Windows
-
Updated
Oct 10, 2025 - C++
NLog Target for Event Tracing for Windows (ETW)
-
Updated
Sep 21, 2025 - C#
Various Windows Performance files, scripts, settings and documents
-
Updated
Aug 19, 2025 - PowerShell
Improve this page
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."