About ETW Internals: Architecture, Hooking, Tampering, and Detection
Event Tracing for Windows is the telemetry fabric behind a large part of modern Windows security work. EDRs, anti-cheats, forensic tools, WPR, Sysmon-adjacent pipelines, and many Microsoft components...
kernullist.github.io