C/C++ Performance Profiler
-
Updated
Nov 14, 2024 - C++
C/C++ Performance Profiler
Adversary tradecraft detection, protection, and hunting
Command line tracing tool for Windows, based on ETW.
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
C# POC to extract NetNTLMv1/v2 hashes from ETW provider
Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
A small real time SyncML protocol Viewer
Simple project that demonstrates how an ETW consumer can be created just by using NTDLL
Command line tool to analyze one/many ETW file/s with simple queries for common issues.
Add a description, image, and links to the etw topic page so that developers can more easily learn about it.
To associate your repository with the etw topic, visit your repo's landing page and select "manage topics."