티스토리 뷰

반응형

왜 ETW를 여러 곳에서 많이 쓰지는 않는지 보니까

파일이나 프로세스, 스레드 이런 건 괜찮은데

네트워크, 레지스트리 등이 너무 난해하군, INTERNALS랑 내부 구조까지 다 알아야 찾겠군

 

https://docs.microsoft.com/en-us/previous-versions//cc750583(v=technet.10)?redirectedfrom=MSDN 

 

Inside the Registry

Table of contents Inside the Registry Article 02/20/2014 23 minutes to read In this article --> Archived content. No warranty is made as to technical accuracy. Content may contain URLs that were valid when originally published, but now link to sites or pag

docs.microsoft.com

https://docs.microsoft.com/en-us/archive/msdn-magazine/2009/october/core-instrumentation-events-in-windows-7-part-2

 

Core Instrumentation Events in Windows 7, Part 2

Table of contents Article 08/13/2015 18 minutes to read In this article --> October 2009 Volume 24 Number 10 Event Tracing for Windows - Core Instrumentation Events in Windows 7, Part 2 By Dr. Insung Park, Alex Bendetov | October 2009 Welcome back for the

docs.microsoft.com

https://social.msdn.microsoft.com/Forums/en-US/ff07fc25-31e3-4b6f-810e-7a1ee458084b/etw-registry-monitoring?forum=etw 

 

ETW - Registry monitoring

Thanks for the reply.  I am beginning to understand how to process registry events.  I think the main thing causing me confusion is inconsistencies between OS versions.  For example, I wrote a test program that creates a new registry key, then closes th

social.msdn.microsoft.com

https://social.msdn.microsoft.com/Forums/en-US/a3365ae1-b152-4e0c-9237-388770b6b638/obatin-the-full-key-path-of-the-registry-event?forum=etw 

 

Obatin the full key path of the registry event

 

social.msdn.microsoft.com

난해하다 난해해

혼란하다 혼란해

 

왜 쉽게 구할 수 있게 만들지 않았을까

친절하지 않아!

 

반응형
댓글
공지사항
최근에 올라온 글
최근에 달린 댓글
Total
Today
Yesterday
링크
«   2025/05   »
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
글 보관함