mirror of
https://github.com/dobin/RedEdr
synced 2026-08-09 12:30:51 +00:00
RedEdr PPL Service
- Used to consume ETW-TI
- Will send it via pipe to main RedEdr
- Requires to be started as PPL service
References:
Communication
RedEdrPplService provides a pipe to interact with it:
#define PPL_SERVICE_PIPE_NAME L"\\\\.\\pipe\\RedEdrPplService"
Which is the pipeServer in control.cpp. It only receives
ASCII commands. Like:
start:<processname>: Observesstop: Indicate RedEdr.exe is being shutdown - disconnectPPL_DATA_PIPE_NAMEshutdown: Shutdown the service (so the exe can be updated)
If RedEdr connects to this pipe, RedEdrPplService will automatically attempt to connect back to RedEdr's pipe:
#define PPL_DATA_PIPE_NAME L"\\\\.\\pipe\\RedEdrPplData"
It will only send the matching events to this pipe.