Skip to content

nasbench/EVTX-ETW-Resources

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 

Repository files navigation

ETW Resources

This is a repository that contains a bunch of resources to learn and understand ETW (Event Tracing for Windows)

Blogs / Research (https://nasbench.medium.com/)

  • A Primer On Event Tracing For Windows (ETW) - [Coming Soon]

Tools

The following are a list of tools that can let us interact with the different ETW providers available. The examples directory contains example scripts and commands on how to use these tools

Interacting w/ ETW

Dumping ETW Providers Manifest

Scripting w/ETW (Detection, Digital Forensics)

Online Resources

The following are blogs and articles published by the wider security community discussing various aspects of ETW

Architecture

Research

Talks

Books