* Add trace parsing from a file instead of realtime
Add a new interface set_trace_filename() that will enable reading from
an ETL file rather than real-time capture.
Also added a new NativeExample that demonstrates this capability.
* Minor cleanup to address code review items.
* Bump nuget version
* added user-mode rundown support
* [bugfix] EVENT_TRACE_FLAG_DISK_FILE_IO enables events for the FileIo provider
* added examples for kernel rundown events (#138)
* added user-mode rundown support to C++/CLI API
* refactor predicate comparers to use std algorithms in place of boost algorithms
* update implementation of contains() to match semantics of boost::contains()
* update implementation based on feedback from PR review
* refactor unecessary use of std::distance and refactor parameter names for consistency with STL
* update solution configuration to remove boost dependency and bump package version
* added new and/or/none predicate functions that compare a vectorlist of arbitrary predicates
* added examples and tests
* reverted visual studio version in krabs.sln
* improved comments in predicate_base
* fixed formatting in user_trace_006_predicate_vectors.cpp
* reverted change to sln
* renamed vector predicates
* updated versions and releaseNotes in nuspec files
* add native support for event filters via API
* not finished:
created one unittest to show usage of native filtering...
* adjust memory usage out of scope....
* file delete event in tests....
* resolving issue 1 in comments of pull request
* issue 2 in pull request comments
* comment 3 in pull request: indentation
* issue 4: identation of if
* excessive comment
* fixed typedef
* removing hungarian convention
* camelCase to snake_case
* snake_case
* fixing more comments in pull request
* uncommenting the first test
* applying comments of pull request
* supporting native event filtering alternated with predicates on other settings
* fix identation
* fixing style
* fixing tabs to spaces
* fix identation
* basing on last change requests except the different method for filterDesc composition which is reasked by me if we could ignore or not.
* fix to reference
* undo excessive change in styling. The file whole written in other style
* fixing indentation of for loop
* - Make projects for Managed and Native example code.
- Create a 'tests' directory.
- Remove SampleCSharpKrabsExe as it is redundant with respect to the example code.
Signed-off-by: Zac Brown (ODSP SECURITY) <zbrown@microsoft.com>
* - Add note about TYPEASSERT and NDEBUG compilation flags to README.md.
- Add /W4 /WX compiler flags to NativeExample project.
- vcxproj.filters updates based on VS magic.
Signed-off-by: Zac Brown (ODSP SECURITY) <zbrown@microsoft.com>