DavidXanatos / priv10

Privacy tool for windows with a built in firewall
https://xanasoft.com/
Other
616 stars 86 forks source link

HOW ETW consumer get full file path in Read/Write Event in native mode #68

Closed yangjian123 closed 3 years ago

yangjian123 commented 3 years ago

can priv10's etw get full file path from etw read/write event in native mode ? i download priv10 source code ,but can not found the solution

DavidXanatos commented 3 years ago

priv10 does now monitor file accesses, but you can use ETW for that purpose, see my task explorer for an example: https://github.com/DavidXanatos/TaskExplorer/blob/master/TaskExplorer/API/Windows/Monitors/EventMonitor.cpp