TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A modern tool for the Windows kernel exploration and observability

91 点作者 cyann超过 4 年前

7 条评论

ComodoHacker超过 4 年前
I&#x27;ve almost typed in a rant about broken layout in the docs section when I noticed the faded hamburger button.<p>Is it the norm now? I personally find it just a bad UI.
评论 #25319191 未加载
评论 #25315877 未加载
saagarjha超过 4 年前
Interesting choice to use Mac-styled stoplight buttons in the demo?
collsni超过 4 年前
Looks like sysmon
评论 #25318446 未加载
评论 #25315494 未加载
GordonS超过 4 年前
This looks interesting, but does it capture the user that performed the a action? I&#x27;ve have a look, and I can&#x27;t see anything about usernames.
评论 #25315760 未加载
eps超过 4 年前
The page says &quot;Loading Fibratus docs...&quot; and that&#x27;s it.
评论 #25319250 未加载
geraldcombs超过 4 年前
Is the kcap file format documented anywhere?
评论 #25322164 未加载
peter_d_sherman超过 4 年前
<a href="https:&#x2F;&#x2F;github.com&#x2F;rabbitstack&#x2F;fibratus&#x2F;blob&#x2F;master&#x2F;docs&#x2F;kevents&#x2F;anatomy.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rabbitstack&#x2F;fibratus&#x2F;blob&#x2F;master&#x2F;docs&#x2F;kev...</a><p>&gt;&quot;Canonical fields<p>Each kernel event contains a series of canonical fields that describe the nature of the event such as its name, the process identifier that generated the event and such. The following is the list of all canonical fields.<p>Sequence is a monotonically increasing integer value that uniquely identifies an event. The sequence value is guaranteed to increment monotonically as long as the machine is not rebooted. After the restart, the sequence is restored to the zero value.<p>PID represents the process identifier that triggered the kernel event.<p>TID is the thread identifier connected to the kernel event.<p>CPU designates the logical CPU core on which the event was originated.<p>Name is the human-readable event name such as CreateProcess or RegOpenKey.<p>Timestamp denotes the timestamp expressed in nanosecond precision as the instant the event occurred.<p>Category designates the category to which the event pertains, e.g. file or thread. Each particular category is explained thoroughly in the next sections.<p>Description is a short explanation about the purpose of the event. For example, CreateFile kernel event creates or opens a file, directory, I&#x2F;O device, pipe, console buffer or other block&#x2F;pseudo device.<p>Host represents the host name where the event was produced.<p>Parameters<p>Also called as kparams in Fibratus parlance, contain each of the event&#x27;s parameters. Internally, they are modeled as a collection of key&#x2F;value pairs where the key is mapped to the structure consisting of parameter name, parameter type and the value. An example of the parameter tuple could be the dip parameter that denotes a destination IP address with value 172.17.0.2 and therefore IPv4 type. Additionally, parameter types can be scalar values, strings, slices, enumerations, and timestamps among others.<p>Process state<p>Each event stores the process state that represents an extended information about the process including its allocated resources such as handles, dynamically-linked libraries, exported environment variables and other attributes. The process state internals are thoroughly explained in the Process events section. (<a href="https:&#x2F;&#x2F;github.com&#x2F;rabbitstack&#x2F;fibratus&#x2F;blob&#x2F;master&#x2F;docs&#x2F;kevents&#x2F;process.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rabbitstack&#x2F;fibratus&#x2F;blob&#x2F;master&#x2F;docs&#x2F;kev...</a>)<p>Metadata<p>Metadata are an arbitrary sequence of tags in form of key&#x2F;value pairs that you can squash into the event on behalf of transformers. A tag can be virtually any string data that you find meaningful to either identify the event or apply filtering&#x2F;grouping once event is persisted in the data store.&quot;<p>PDS: It would be interesting if a future OS -- <i>was completely designed around such a descriptive Event Log at its heart</i>...<p>That is, the future OS -- would automatically put ALL of its events into such an Event Log in memory, where programmers, through various tools and means (much like Fibratus) could ask it to filter out and log messages of interest, if they had appropriate rights.<p>Yes, it might be slow to do this... but perhaps there would be software&#x2F;algorithmic mitigations to that...<p>For logging&#x2F;capturing OS events (in this case, Windows 7+, but perhaps in the future, any OS, or future OS&#x27;es that are specifically designed for it),<p><i>Fibratus has a lot of good ideas!</i>