Volltext-Downloads (blau) und Frontdoor-Views (grau)
The search result changed since you submitted your search request. Documents might be displayed in a different sort order.
  • search hit 10 of 21
Back to Result List

Insight into Event Tracing for Windows

  • The core logging and tracing facility in Windows operating system is called Event Tracing for Windows (ETW). Data sources providing events for ETW are instrumented all over the operating system. That means most hard- and software assets in a Windows system are instrumented with ETW and so are able to contribute low-level information. ETW can be used by developers and administrators to getThe core logging and tracing facility in Windows operating system is called Event Tracing for Windows (ETW). Data sources providing events for ETW are instrumented all over the operating system. That means most hard- and software assets in a Windows system are instrumented with ETW and so are able to contribute low-level information. ETW can be used by developers and administrators to get low-level information about operating system's activity. We describe existing tools to interact with the ETW faciltity and evaluate them based on defined criteria. Based on relevant application scenarios, we show the richness of informational content for debugging or detecting security incidents with ETW. The widely used instrumentation of ETW in the operating system and its application results also in security risks according to confidentiality. Based on common ETW providers we show the impact to confidentiality what ETW offers an adversary. At the end we evaluate solutions and approaches for a customizable telemetry infrastructure using ETW in large-scale environments.show moreshow less

Download full text files

  • Thesis_Schlabach, Thomas
    eng

Export metadata

Additional Services

Share in Twitter Search Google Scholar

Statistics

frontdoor_oas
Metadaten
Author:Thomas Schlabach
Contributing Corporation:Enno Rey Netzwerke GmbH (ERNW)
Place of publication:Offenburg
Year of Publication:2019
Pagenumber:viii, 61
Language:English
Tag:Event Tracing for Windows; Logging; Telemetry; Windows
DDC classes:000 Allgemeines, Informatik, Informationswissenschaft
Advisor:Andreas Schaad, Aleksander Milenkoski
Publishing Institution:Hochschule Offenburg
Granting Institution:Hochschule Offenburg
Date of final exam:2019/07/29
Document Type:Bachelor Thesis
Institutes:Abschlussarbeiten / Bachelor-Studiengänge / UNITS
Open Access:Zugriffsbeschränkt
Release Date:2019/09/24
Licence (German):License LogoEs gilt das UrhG