ION28 / BLUESPAWN

An Active Defense and EDR software to empower Blue Teams
GNU General Public License v3.0
1.22k stars 169 forks source link

Finally add ETW module #383

Closed CalvinKrist closed 3 years ago

ION28 commented 3 years ago

Highly recommend looking into https://github.com/zodiacon/ProcMonXv2

@Jack-McDowell might have some other suggested examples. I'll look for others tomorrow as well

ION28 commented 3 years ago

Another good resource https://github.com/pathtofile/Sealighter

Both are c++ etw projects with a security focus / connection which go beyond the krabsetw examples

CalvinKrist commented 3 years ago

Closed because there's a better way in the works