Many ETW events are extremely useful for cyber security, but are not (well) documented. 😞 For example, the Kernel-Audit-API-Calls provider sounds interesting, but all of the events are called task_nn ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results