Cool win-thingies
My repository for doing dfir windows things in real time.
Scripts
scripts/etw_mon.py
See etw_mon docs
scripts/userassist_monitor.py
scripts/print_handles.py
scripts/print_publishers.py
Thanks
Thanks to other people's work that were great win32 ctype references.