Correlating kernel notifications with the lack of ETW events to detect ETW Patching
-
Updated
Mar 14, 2026 - C++
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
High-performance ETW (Event Tracing for Windows) consumer library for Python with Rust core
Experimental agent trace recorder for JEP/HJS/JAC incident review and chain reconstruction.
Add a description, image, and links to the event-tracing topic page so that developers can more easily learn about it.
To associate your repository with the event-tracing topic, visit your repo's landing page and select "manage topics."