Tool for exploration and tracing of the Windows kernel
Project description
Fibratus is a tool which is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which encapsulates the machinery to start the kernel event stream collector, set kernel event filters or run the lightweight Python modules called filaments. You can use filaments to extend Fibratus with your own arsenal of tools.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
fibratus-0.7.2.tar.gz
(213.6 kB
view details)
File details
Details for the file fibratus-0.7.2.tar.gz
.
File metadata
- Download URL: fibratus-0.7.2.tar.gz
- Upload date:
- Size: 213.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 7c6ceab4bf90b4cc509b03cad69ad60865fb79183579c1feb4658169902e754c |
|
MD5 | e2cc29b8f101b4cf4b40778b5970a7b3 |
|
BLAKE2b-256 | dad9b8a8090636c3fd7e29e73dc7427bad70739aca3891a6c4d0d1fdb28df772 |