Event tracing for Windows (ETW) is a href="https://support.microsoft.com/en-us/help/2593157/event-tracing-for-windows-etw-simplified">lightweight
logging facility first introduced with Windows 2000. Originally
intended as a software diagnostic, troubleshooting and performance
monitoring tool, it was greatly expanded in Windows Vista to create a
href="https://blogs.msdn.microsoft.com/ntdebugging/2009/08/27/part-1-etw-introduction-and-overview/">lightweight
debugging mechanism.
The basic architecture of ETW has three discrete components:
providers, controllers, and consumers. The providers supply the trace
data, controllers control capture sessions, and the consumers process
the data returned from the providers. Figure 1 shows an overview of
this architecture.

Figure 1: ETW Architecture
Windows 7 has more than 600 providers installed by default, many of
which provide verbose trace data. ETW data can be used to conduct
research into almost any area of the OS without the need for a
debugger. A default Windows installation ships with all the tools
needed to capture ETW data, but these tools are somewhat inflexible.
Another drawback is that a different tool is usually needed when
analyzing the captured data.
Prior to making the decision to create an entirely new project,
research was conducted to see if there was an existing project that
would work. Several projects were found, with href="https://github.com/Microsoft/krabsetw">KrabsETW from
Microsoft and href="https://github.com/sebmarchand/pyetw">Google’s pyetw
looking the most promising. Neither of these were quite right,
however, since KrabsETW is not written in Python and therefore not
compatible with existing projects, and pyetw is no longer maintained.
We found simple programmatic access to ETW using Python was missing.
Pywintrace is a
Python package developed by the FireEye Innovation and Custom
Engineering (ICE) team to fill the need for a flexible wrapper around
Windows APIs to accelerate ETW research. Using Python’s ctypes, the
team created a module that can create and control a capture session,
as well as process trace events. The package contains three main classes: