A modern tool for Windows kernel exploration and tracing with a focus on security
--image
flag)RenameFile
and SetFileInformation
kernel eventspid
and file_object
fields in file system eventslogbook
for detailed startup logging info--pid
command line flag)--cswitch
command line flag to enable context switch kernel eventsprocess
method on filamentRegSetValue
or RegQueryValue
setup.py
to install kstreamc to site-packages--no-enum-handles
to disable the system handles enumeration on startup