System Activity Monitor (SAM) is a research tool that enables detailed recording of system and application behavior and resource usage.
-
Updated
Sep 8, 2022 - C++
System Activity Monitor (SAM) is a research tool that enables detailed recording of system and application behavior and resource usage.
Bypassing Event Tracing for Windows (ETW) with CSharp
Open Power Performance Analysis Tool
A simple example application to collect DNS queries logs using etw-api
This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing
Simple project that demonstrates how an ETW consumer can be created just by using NTDLL
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
C/C++ Performance Profiler
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."