Skip to content

How can i add filters in ETW #320

@ShubhAgrwlKiteCyber

Description

@ShubhAgrwlKiteCyber

I am utilizing the Microsoft-Windows-Kernel-File provider to capture file system events. However, rather than capturing events across the entire system, I aim to apply targeted filtering based on specific, predefined directories. The goal is to ensure that only events related to operations performed within these directories are captured. This will allow the ETW (Event Tracing for Windows) to efficiently filter and forward only the relevant events for further processing, minimizing unnecessary overhead and focusing on the directories of interest.

How it can be done?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions