Command line tracing tool for Windows, based on ETW.
-
Updated
Jan 16, 2024 - C#
Command line tracing tool for Windows, based on ETW.
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
A small real time SyncML protocol Viewer
.NET Logging adaptors
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Collects network traces of .NET applications.
Logs key Windows process performance metrics. #nsacyber
ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
A Splunk Technology Add-on to forward filtered ETW events.
Visual Studio Extension and tools to ease development using Event Tracing for Windows (ETW).
NLog Target for Event Tracing for Windows (ETW)
An ETW EventSource Tracing Core build on .Net Standard 2.0
An Event Tracing for Windows (ETW) EventSource generator built on .Net Core 2.0
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."