📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  win32 syscall tracing

Topic created on: February 5, 2009 04:35 CST by pazuzu .

Hi,

I'm looking for an equivalent of the 'strace' command from Linux running under Windows. It is a tool to trace all system calls made by a process, it's child processes or loaded libraries. I've tried StraceNT but unfortunately it doesn't seem to report syscalls made by child processes and by external DLLs loaded by the process. I haven't found any other tools besides StraceNT working under Windows XP. Are there any better tools to trace a process ? I'm also not only interested in the mere fact, that a process calls syscal X but what the actual arguments for it are.

  Styx     February 5, 2009 05:35.13 CST
you can use kam: http://ww.kakeeware.com
but there is now such usefull equivallent as strace for windoze.

  ZuTLe     February 5, 2009 06:08.04 CST
Check out API Monitoring Tools at Collaborative RCE Tool Library.

Remember to gief cred to dELTA and the crew :)

  dELTA     February 5, 2009 10:23.22 CST
And if you really mean "system calls" as in "kernel level calls", you might want to take a look at the SysCall Monitoring Tools category too (or instead). :)

  pazuzu   February 7, 2009 13:55.47 CST
Thanks for your help guys :). My RE toolkit just got a lot more complete.

  q258   February 11, 2009 16:42.51 CST
Haven't tried `em personally but:

http://download.microsoft.com/download/platformsdk/sample63/1/w31/en-us/stktrace.exe

http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit