Winshark

ETW decoder

A Wireshark plugin for instrumenting Event Tracing for Windows

A wireshark plugin to instrument ETW

GitHub

537 stars
28 watching
59 forks
Language: Lua
last commit: over 4 years ago
etwpcapwireshark

Related projects:

RepositoryDescriptionStars
airbus-cert/regrippyA Python-based framework for reading and extracting forensics data from Windows registry hives188
roddypratt/tslumd-wiresharkWireshark dissector for decoding TSL UMD protocol packets in network traffic5
airbus-cert/ttddbgA plugin for IDA Pro that allows time travel debugging and supports loading of WinDBG Preview traces553
jdu2600/windows10etweventsCollects and analyzes Windows 10 event tracing data from various providers across different versions.275
airbus-cert/dnyaraA .Net wrapper library for the native Yara library to quickly identify and classify malware samples.38
airbus-cert/comidaAn IDA plugin to analyze COM module usage and infer types for easier analysis.199
sasa1977/site_encryptA library for automatic SSL/TLS certificate management in Elixir web applications474
psi-4ward/asksinanalyzerxsAn analyzer tool for decoding and processing radio telegrams in HomeMatic environments48
chugr/adverbTools for distilling and displaying network trace data in an interactive web page format12
ctron/yew-oauth2An OAuth2 component for Yew web applications.45
flyq/ecdsa_pocAn educational proof-of-concept demonstrating the verification of ECDSA signatures using a custom-built backend in Motoko language0
cert-polska/n6A system to collect and manage security information on a large scale.124
eth0izzle/bucket-streamTools to identify publicly accessible S3 buckets by monitoring certificate transparency logs.1,756
olliw42/otxtelemetryProvides MAVLink telemetry capabilities to OpenTx autopilot systems38
boku7/injectetwbypassTool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall276