
Standalone zero-driver Windows system and API monitor in Rust
High-performance zero-driver Windows system and API monitor in Rust.
Modern strace and real-time Process Monitor for Windows. Built in native Rust with zero kernel drivers required, featuring a real-time terminal user interface (TUI) and unbuffered streaming for headless diagnostics.
powershell -ExecutionPolicy Bypass -File .\packaging\install.ps1
Installs wstrace.exe to $HOME\.local\bin and registers the directory into the User PATH environment variable.
winget install gilnett.wstrace
scoop install packaging/scoop/wstrace.json
cargo install --path .
Compile directly using the Rust toolchain:
cargo build --release
The resulting standalone executable is located at target\release\wstrace.exe.
Confirm that wstrace is accessible in the current shell:
wstrace --version
Launches the target application with a real-time event table:
wstrace run <executable_path> [-- <arguments>...]
| Key | Action | Description |
|---|---|---|
Ctrl+C | Copy Selected | Copies the highlighted event details into the Windows clipboard. |
Ctrl+A | Copy All | Copies all currently filtered events into the Windows clipboard. |
Ctrl+E / Space | Pause / Resume | Freezes the event view without dropping incoming telemetry. |
Ctrl+X | Clear Buffer | Empties the current event list from the display buffer. |
Tab | Category Cycle | Filters events: ALL -> FILE -> REG -> NET -> PROC. |
f | Failures Only | Restricts view to failed operations (e.g. access denied, not found). |
Up / Down | Navigation | Selects an event for deep inspection. |
q / Esc | Exit | Terminates the tracing session cleanly. |
Attach to an existing process by Process Identifier (PID) or binary name without restarting it:
# Attach by PID
wstrace attach -p <PID>
# Attach by process executable name
wstrace attach -n <process_name.exe>
-C / --children)Tracks the target process and recursively monitors all child processes spawned by it:
wstrace -C run <executable_path> [-- <arguments>...]
--include and --exclude)Isolate relevant operations or suppress operating system noise:
# Include only operations matching a substring
wstrace --include "<substring>" run <executable_path>
# Exclude operations matching a substring
wstrace --exclude "<substring>" run <executable_path>
-m stream)Writes live events directly to stdout with ANSI color codes for logging or CI/CD pipelines:
wstrace -m stream [-d <seconds>] run <executable_path>
--export-json)Exports all captured session events to a formatted JSON file upon termination:
wstrace --export-json <output_file.json> run <executable_path>
--copy / --to-clipboard)Automatically copies all captured session events directly to the Windows clipboard upon exit:
wstrace --copy run <executable_path>
packaging/install.ps1)ToolHelp32Snapshot, OpenProcess, VirtualQueryEx) & Event Tracing for Windows (ETW).x86_64-pc-windows-msvc (Intel / AMD 64-bit)aarch64-pc-windows-msvc (Qualcomm Snapdragon X / Windows on ARM)wstrace is engineered to meet strict institutional requirements for deployment in high-security enterprise environments (banking, defense, healthcare, and critical infrastructure):
wstrace is 100% offline and standalone. It maintains zero remote servers, initiates zero telemetry or analytics, and performs zero outbound network calls. Any sensitive data observed during live tracing (API tokens, file paths, credentials, memory contents) remains strictly confined to local RAM and never leaves the workstation.
Unlike traditional tracing utilities that install third-party .sys kernel drivers—introducing system crash risks (Blue Screen of Death / BSOD) and ring-0 backdoor attack surfaces—wstrace operates with zero kernel drivers. It relies exclusively on non-invasive userland Win32 debugging and native Windows Kernel ETW consumer interfaces.
Trace telemetry is strictly bounded by the Windows user session and Mandatory Integrity Control (MIC) boundaries. Unprivileged user sessions cannot access or inspect higher-integrity processes without explicit administrator elevation, adhering strictly to the principle of least privilege.
wstrace is proud to build upon the Rust open-source ecosystem and acknowledges the following foundational libraries: