How to consume real-time ETW events from the Microsoft-Windows-NDIS-PacketCapture provider?

前端 未结 4 739
日久生厌
日久生厌 2021-02-03 11:19

The larger question is how to consume real-time ETW network stack events in general but I\'m particularly interested in the Microsoft-Windows-NDIS-PacketCapture provider

4条回答
  •  旧时难觅i
    2021-02-03 12:16

    Here's a commented c++ example application that demonstrates simultaneous real-time ETW sessions for packet capture and kernel events.

    https://github.com/packetzero/etwrealtime

提交回复
热议问题