Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wstrace — Standalone zero-driver Windows system and API monitor in Rust | Kitploit
Tools/GitHubGitHub/gilnett/wstrace
Defensive ToolsDynamic Analysis (Sandboxing)Reverse EngineeringDebuggersForensicsInformation GatheringMalware AnalysisBinary AnalysisIncident ResponseLog Analysis
GitHubgilnett/wstrace
291 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

wstrace

Standalone zero-driver Windows system and API monitor in Rust

View Repository
Share

wstrace logo

wstrace

High-performance zero-driver Windows system and API monitor in Rust.

License: GPL-3.0 GitHub Sponsors Ko-fi

Modern strace and real-time Process Monitor for Windows. Built in native Rust with zero kernel drivers required, featuring a real-time terminal user interface (TUI) and unbuffered streaming for headless diagnostics.


Installation

PowerShell Script

powershell -ExecutionPolicy Bypass -File .\packaging\install.ps1

Installs wstrace.exe to $HOME\.local\bin and registers the directory into the User PATH environment variable.

Windows Package Manager (Winget)

winget install gilnett.wstrace

Scoop

scoop install packaging/scoop/wstrace.json

Cargo (From Source)

cargo install --path .

Prebuilt Binary

Compile directly using the Rust toolchain:

cargo build --release

The resulting standalone executable is located at target\release\wstrace.exe.


Usage Guide

Verification

Confirm that wstrace is accessible in the current shell:

wstrace --version

Interactive TUI Mode

Launches the target application with a real-time event table:

wstrace run <executable_path> [-- <arguments>...]

TUI Keyboard Controls

KeyActionDescription
Ctrl+CCopy SelectedCopies the highlighted event details into the Windows clipboard.
Ctrl+ACopy AllCopies all currently filtered events into the Windows clipboard.
Ctrl+E / SpacePause / ResumeFreezes the event view without dropping incoming telemetry.
Ctrl+XClear BufferEmpties the current event list from the display buffer.
TabCategory CycleFilters events: ALL -> FILE -> REG -> NET -> PROC.
fFailures OnlyRestricts view to failed operations (e.g. access denied, not found).
Up / DownNavigationSelects an event for deep inspection.
q / EscExitTerminates the tracing session cleanly.

Attach to Running Process

Attach to an existing process by Process Identifier (PID) or binary name without restarting it:

# Attach by PID
wstrace attach -p <PID>

# Attach by process executable name
wstrace attach -n <process_name.exe>

Child Process Tracking (-C / --children)

Tracks the target process and recursively monitors all child processes spawned by it:

wstrace -C run <executable_path> [-- <arguments>...]

Path Filtering (--include and --exclude)

Isolate relevant operations or suppress operating system noise:

# Include only operations matching a substring
wstrace --include "<substring>" run <executable_path>

# Exclude operations matching a substring
wstrace --exclude "<substring>" run <executable_path>

Headless Stream Mode (-m stream)

Writes live events directly to stdout with ANSI color codes for logging or CI/CD pipelines:

wstrace -m stream [-d <seconds>] run <executable_path>

Structured JSON Export (--export-json)

Exports all captured session events to a formatted JSON file upon termination:

wstrace --export-json <output_file.json> run <executable_path>

Clipboard Export (--copy / --to-clipboard)

Automatically copies all captured session events directly to the Windows clipboard upon exit:

wstrace --copy run <executable_path>

Architecture & Compatibility

  • Core Engine: Rust (2021 Edition)
  • Installer & Deployment: PowerShell (packaging/install.ps1)
  • Terminal UI: Ratatui + Crossterm
  • Telemetry Ingestion: Win32 APIs (ToolHelp32Snapshot, OpenProcess, VirtualQueryEx) & Event Tracing for Windows (ETW).
  • Target Architectures:
    • x86_64-pc-windows-msvc (Intel / AMD 64-bit)
    • aarch64-pc-windows-msvc (Qualcomm Snapdragon X / Windows on ARM)

Enterprise Compliance & Institutional Governance

wstrace is engineered to meet strict institutional requirements for deployment in high-security enterprise environments (banking, defense, healthcare, and critical infrastructure):

1. Zero Cloud Data Leakage (Air-Gapped & Sovereign)

wstrace is 100% offline and standalone. It maintains zero remote servers, initiates zero telemetry or analytics, and performs zero outbound network calls. Any sensitive data observed during live tracing (API tokens, file paths, credentials, memory contents) remains strictly confined to local RAM and never leaves the workstation.

2. Zero Kernel Drivers (Zero Ring-0 Footprint)

Unlike traditional tracing utilities that install third-party .sys kernel drivers—introducing system crash risks (Blue Screen of Death / BSOD) and ring-0 backdoor attack surfaces—wstrace operates with zero kernel drivers. It relies exclusively on non-invasive userland Win32 debugging and native Windows Kernel ETW consumer interfaces.

3. Strict Local Access Control & Session Isolation

Trace telemetry is strictly bounded by the Windows user session and Mandatory Integrity Control (MIC) boundaries. Unprivileged user sessions cannot access or inspect higher-integrity processes without explicit administrator elevation, adhering strictly to the principle of least privilege.

4. Regulatory & Standard Alignment

  • SOC 2 Type II & ISO/IEC 27001 Alignment: Complete data sovereignty, zero external data egress, and auditable build provenance.
  • GDPR (RGPD) & CCPA Compliance: Privacy by Design architecture. Zero personal data collection, profiling, tracking, or commercialization.
  • EU Cyber Resilience Act (CRA) Readiness: Documented security disclosure policy (SECURITY.md), automated CVE dependency scanning via Dependabot, and third-party license audit inventory (THIRD_PARTY_LICENSES.md).
  • OWASP Rule #1 Compliance: Zero hardcoded secrets, credentials, or private API keys across the codebase and version control history.

License & Intellectual Property Governance

  • Software License: Licensed under the GNU General Public License v3.0 (GPL-3.0-or-later).
  • Contributor License Agreement (CLA): All external contributions are subject to the terms outlined in CONTRIBUTING.md, ensuring unified copyright ownership and protecting corporate acquisition (M&A) and commercial dual-licensing rights.

Acknowledgements & Third-Party Credits

wstrace is proud to build upon the Rust open-source ecosystem and acknowledges the following foundational libraries:

  • Ratatui (MIT) — Modern terminal user interface (TUI) layout and rendering engine.
  • Crossterm (MIT) — Cross-platform terminal manipulation and raw input control.
  • windows-sys (MIT / Apache-2.0) — Official Microsoft Win32 and Kernel ETW API bindings.
Download Tool