KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
active 2023-08-16 → 2026-08-17 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 1098 days from 2023-08-16 to 2026-08-17. Pushes: 32 total, peak 9 in a day. Pull requests: 36 total, peak 5 in a day. Issues: 47 total, peak 10 in a day. Comments: 130 total, peak 12 in a day. Stars: 188 total, peak 3 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| kylereedmsft | 76 | 14 | 10 | 23 |
| swannman | 70 | 8 | 7 | 33 |
| wwh1004 | 24 | 0 | 4 | 11 |
| starix | 15 | 0 | 1 | 7 |
| HydrophobicMinghao | 11 | 0 | 3 | 6 |
| vmurthysuhas | 11 | 3 | 0 | 2 |
| jdu2600 | 10 | 0 | 0 | 9 |
| mjeong92 | 7 | 4 | 3 | 0 |
| clemenswasser | 7 | 0 | 0 | 6 |
| henriblMSFT | 7 | 3 | 1 | 0 |
| microsoft-github-policy-service[bot] | 6 | 0 | 0 | 6 |
| kaaleksandr | 5 | 0 | 2 | 2 |
| dobin | 5 | 0 | 0 | 3 |
| jrmuizel | 5 | 0 | 0 | 5 |
| mihai12p | 4 | 0 | 1 | 3 |
| gleen-code | 3 | 0 | 0 | 1 |
| Kwansy98 | 3 | 0 | 0 | 1 |
| Cishanduwang | 3 | 0 | 0 | 1 |
| SpencerTSmith | 3 | 0 | 0 | 1 |
| rjadidi920 | 2 | 0 | 0 | 1 |
Recent activity
Latest issues, pull requests and releases
- Issue comment#275jdu26002026-04-17 05:12replace name->property map with hinted linear scan
- Issue comment#277jurif307-blip2026-04-07 18:36IDL TYPELIB FROM OLE-COM MITEC.CZ IS THE FIRST STEP FOR SUCCESSFUL .H AND .C FILES. FOR EXAMPLE : APACHE AVRO USES IDL AND THEN HEADER FILE
- Issue comment#273swannman2026-03-27 22:51Parser performance
- Issue#263swannman2025-12-09 18:33Feature request - store user-defined context inside trace
- Issue#262swannman2025-12-09 18:32how to use winkernel-network for TCP/IP event ?
- Issue comment#259swannman2025-12-09 18:32error: integer value 31 is outside the valid range of values [0, 1] for the enumeration type '_SYSTEM_INFORMATION_CLASS'
- Issue#247swannman2025-12-09 18:29How to access member of a class during inside callback function ?
- Issue#188swannman2025-12-09 18:22ImageFileName cannot be parsed with wstring?
- Issue#183swannman2025-12-09 18:22Compilation error with Windows Kit 8.1 (EventNameOffset)
- Issue#208swannman2025-12-09 18:10How to get the user mode call stack
- Issue#203swannman2025-12-09 18:10heap alloc etw don't work
- Issue#192swannman2025-12-09 18:09Service Control Manager
- Issue#225swannman2025-12-09 18:09Why Service Control Manager provider doesn't generate any event id?
- Issue#246swannman2025-12-09 18:08Question: can I use krabsetw for past events?
- Issue comment#268lxwAsm2025-12-09 03:02how can i get process_id in krabs::kernel::network_tcpip_provider callback, please
- Issue comment#268swannman2025-12-08 17:33how can i get process_id in krabs::kernel::network_tcpip_provider callback, please
- Issue comment#265swannman2025-12-01 20:40Add constructor for schema from EVENT_RECORD and PTRACE_EVENT_INFO
- Issue#266mediantt2025-11-23 07:19event_filter callbacks - no "move" overload
- Pull request#267kylereedmsft2025-11-20 00:11
- Issue comment#266kylereedmsft2025-11-19 21:39event_filter callbacks - no "move" overload
- Issue#266mediantt2025-11-19 11:11event_filter callbacks - no "move" overload
- Issue comment#237Scullywagon2025-08-19 08:40Getting PMC data
- Issue comment#260Scullywagon2025-08-19 08:33Can't find schema for context_switch_provider
- Issue comment#264swannman2025-06-14 00:09Logging to ETL file
- Issue#264valleyofdoom2025-06-13 23:44Logging to ETL file
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 188 stars here means stars gained during the window, not the repo's star count.