drakvuf
drakvuf copied to clipboard
need guidance towards drakvuf tracing
Dear Tamas K. Lengyel Sir,
From previous instructions by you, we have successfully generated some logs.
In logs we found some extra features like -
- Syscall Time
- Sysret Time
- Delayintervals
- Process Handler
- Process Information Class
- Process Information
- Return Length
- CR3 Value
- Procmon
- Filetracer
- Sysnet
- File Extractor
- Syscall
- Poolmon
- Delaymon
- Objmon
We now request you to guide us by providing any documentation or description of these features and what they are indicating.
Kindly provide your guidance so that we can move ahead further. Thanks
Regards Mohit
e.g. https://learn.microsoft.com/en-us/windows/win32/api/ https://learn.microsoft.com/en-us/sysinternals/resources/windows-internals https://learn.microsoft.com/en-us/sysinternals/resources/