AlienVault-Engineering / libetw

Simple C++ library for Windows ETW event access

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

libetw

Simple C++ library for Windows ETW event access

Features

  • Kernel Processes and Tcp Events
  • Dns Addresses

Work in progress

The IPC, FileIO Volume are a work in progress.

Build With Tests

mkdir build
cd build
set MAKE_TESTS=1
set GTEST_DIR=/c/Users/Devo/gtest
cmake -G "Visual Studio 14 Win64" ..

About

Simple C++ library for Windows ETW event access

License:Apache License 2.0


Languages

Language:C++ 96.0%Language:C 2.5%Language:CMake 1.5%