0xcpu / bnetwbreaker

BinaryNinja plugin for ETW events parsing

Repository from Github https://github.com0xcpu/bnetwbreakerRepository from Github https://github.com0xcpu/bnetwbreaker

BinaryNinja etwbreaker

A BinaryNinja plugin to statically find ETW events in a PE file and generate a report.

This plugin is an adaptation of etwbreaker (Thank you @airbus-cert!). Please read original description to understand better the purpose of this plugin.

Current version doesn't support (conditional) breakpoints.

How to install?

Please refer to BinaryNinja's user documentation.

About

BinaryNinja plugin for ETW events parsing

License:Apache License 2.0


Languages

Language:Python 100.0%