OrbitC/C++ Performance Profiler
ETWProcessMon2ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
ETW2JSONTool and library to convert ETW logs to JSON files
PRUNELogs key Windows process performance metrics. #nsacyber
PSTraceTrace ScriptBlock execution for powershell v2
ferrisetwBasically a KrabsETW rip-off written in Rust
ETWNetMonv3ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Splunk-ETWA Splunk Technology Add-on to forward filtered ETW events.
TA ETWSplunk Technology Add-On (TA) for collecting ETW events from Windows systems