Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le septembre 19, 2017, 23:00:39

Titre: [FireEye]Introducing pywintrace: A Python Wrapper for ETW
Posté par: igor51 le septembre 19, 2017, 23:00:39
Introducing pywintrace: A Python Wrapper for ETW

[html]

Introduction


 

Event tracing for Windows (ETW) is a     href="https://support.microsoft.com/en-us/help/2593157/event-tracing-for-windows-etw-simplified">lightweight
    logging facility first introduced with Windows 2000. Originally
  intended as a software diagnostic, troubleshooting and performance
  monitoring tool, it was greatly expanded in Windows Vista to create a
        href="https://blogs.msdn.microsoft.com/ntdebugging/2009/08/27/part-1-etw-introduction-and-overview/">lightweight
    debugging mechanism.


 

The basic architecture of ETW has three discrete components:
  providers, controllers, and consumers. The providers supply the trace
  data, controllers control capture sessions, and the consumers process
  the data returned from the providers. Figure 1 shows an overview of
  this architecture.


 


 
 
 Figure 1: ETW Architecture


 

Windows 7 has more than 600 providers installed by default, many of
  which provide verbose trace data. ETW data can be used to conduct
  research into almost any area of the OS without the need for a
  debugger. A default Windows installation ships with all the tools
  needed to capture ETW data, but these tools are somewhat inflexible.
  Another drawback is that a different tool is usually needed when
  analyzing the captured data.


 

Prior to making the decision to create an entirely new project,
  research was conducted to see if there was an existing project that
  would work. Several projects were found, with     href="https://github.com/Microsoft/krabsetw">KrabsETW from
  Microsoft and     href="https://github.com/sebmarchand/pyetw">Google’s pyetw
  looking the most promising. Neither of these were quite right,
  however, since KrabsETW is not written in Python and therefore not
  compatible with existing projects, and pyetw is no longer maintained.
  We found simple programmatic access to ETW using Python was missing.


 

Enter pywintrace


 


  Pywintrace is a
  Python package developed by the FireEye Innovation and Custom
  Engineering (ICE) team to fill the need for a flexible wrapper around
  Windows APIs to accelerate ETW research. Using Python’s ctypes, the
  team created a module that can create and control a capture session,
  as well as process trace events. The package contains three main classes: