Skip to content

@rabbitstack rabbitstack released this Jul 22, 2017 · 5 commits to master since this release

  • fixes skips filtering on Windows 7 (fs / dll events)
  • kstreamc now keeps a separate thread map to bind thread to its process
Assets 3

@rabbitstack rabbitstack released this Apr 17, 2017 · 13 commits to master since this release

  • spying on a specific process image (--image flag)
  • file system output
  • configuration file validation through schema definition
  • fixed C to Python data type castings
Assets 3

@rabbitstack rabbitstack released this Mar 24, 2017 · 50 commits to master since this release

  • integration with YARA tool
  • standalone Windows installer
  • minor bug fixes and code refactoring
Assets 3

@rabbitstack rabbitstack released this Mar 4, 2017 · 80 commits to master since this release

  • support for RenameFile and SetFileInformation kernel events
  • pid and file_object fields in file system events
  • filament processing in thread context
  • several bug fixes
Assets 2

@rabbitstack rabbitstack released this Jan 22, 2017 · 95 commits to master since this release

  • high performance GIL-free kernel event stream collector
  • image meta registry provides PE (Portable Exectuable) headers, sections, imports, file information, etc
  • streaming kernel events to multiple output sinks
  • switched to logbook for detailed startup logging info
Assets 2

@rabbitstack rabbitstack released this Nov 5, 2016 · 166 commits to master since this release

  • authentication support for elasticsearch output adapter
Assets 2

@rabbitstack rabbitstack released this Nov 1, 2016 · 168 commits to master since this release

  • per-pid process spying support (--pid command line flag)
  • excluding processes from the trace through the configuration file
  • ElasticSearch output adapter
  • performance improvements on the kernel stream collector
Assets 2

@rabbitstack rabbitstack released this Oct 1, 2016 · 196 commits to master since this release

  • context switch instrumentation support
  • --cswitch command line flag to enable context switch kernel events
Assets 2

@rabbitstack rabbitstack released this Aug 20, 2016 · 233 commits to master since this release

  • minor changes to MANIFEST.in artifact
  • installing via pip
Assets 2
Aug 20, 2016
included setuptools manifest
You can’t perform that action at this time.