n4r1b / ferrisetw

Basically a KrabsETW rip-off written in Rust
Other
64 stars 23 forks source link

Implement event filtering #6

Open n4r1b opened 3 years ago

n4r1b commented 3 years ago

Info ETW allows filters to be defined for a Provider in a session. MSDN - Defining Filters. KrabsETW already provides a mechanism to do filtering either by events_id or by using more complicated predicates

TODO

daladim commented 1 year ago

We're now able to filter by Event ID.

Predicates are left TODO