wusstrace


A user-space syscall tracer for Microsoft Windows

WUSSTrace is a user-space syscall tracer for Microsoft Windows developed for fine grained syscall tracing: it supports the majority of Windows system calls (except GUI system calls), the majority of argument types, and dumps faithfully all the supported types. WUSSTrace produces easy-to-parse XML traces leveraging the Boost serialization library. Tracing is performed by injecting a shared library in the address space of the traced process and by hooking the stubs KiFastSystemCall and KiIntSystemCall in ntdll.dll.

Project Information

  • License: GNU GPL v3
  • 11 stars
  • svn-based source control

Labels:
systemcalltracing malware strace reverseengineering