/PowerTrace

A Powershell module containing commands to control and process ETW (Event Tracing for Windows).

Primary LanguagePowerShellMIT LicenseMIT

PowerTrace

PowerTrace is a PowerShell module containing various commands to help you work with ETW events and sessions.

Available commands

Invoke-Wtrace

Runs wtrace - a command line tool, which shows process activities (FileIO, TCP/IP, RPC, ALPC)