Skip to content

Releases: mandiant/STrace

v1.3.6

29 Oct 20:02
Compare
Choose a tag to compare
  • Use SeLocateProcessImageName to read process name

v1.3.5

29 Oct 02:16
7e2d56c
Compare
Choose a tag to compare
  • Read full process name and path by reading usermode PEB (Wow64 & Native). CallerInfo buffer is now 100 character limit.

v1.3.4

12 Apr 00:22
a332181
Compare
Choose a tag to compare
  • Change PDBReSym commandline

v1.3.3

10 Apr 17:15
af73d55
Compare
Choose a tag to compare
  • Add PDBReSym release

v1.3.2

09 Jan 22:23
Compare
Choose a tag to compare

Updates release to master to fix some crashes

v1.3.1

23 Aug 16:43
Compare
Choose a tag to compare
  • Updates PDBReSym utility dependencies and refactors command line argument groups
  • Add new getpdb subcommand

v1.3

18 Aug 19:49
d467aba
Compare
Choose a tag to compare

Adds the ability to create ETW Providers and write events to them.

v1.2

19 Jan 18:55
baa2e8a
Compare
Choose a tag to compare

Fixes some ETW logic and syncs with current master.

v1.1

26 Oct 19:50
Compare
Choose a tag to compare
  • Decreases stack usage in some plugins
  • Fixes a critical bug in read_argument
  • Updates to multiple plugins

Initial Release

04 Oct 18:31
0a1d3cc
Compare
Choose a tag to compare
Merge pull request #8 from kirbyUK/main

Initial ETW probe support