Skip to content

Version 0.3

Pre-release
Pre-release
Compare
Choose a tag to compare
@dobin dobin released this 06 Jan 20:04
· 20 commits to master since this release

I made it work. After this, i make it nice.

  • More robust ETW events by switching to KrabsETW
  • More robust ntdll.dll hooking by patching all the bugs
  • Way less crashes
  • The JSON format has somewhat stabilized
  • Reliable callstack addresses memory info
  • Basic ETW detections
  • Tested with some C2