MCPcopy Create free account
hub / github.com/ELMERIKH/PyinMemoryPE / process

Method process

windows/winobject/event_trace.py:249–301  ·  view source on GitHub ↗

Process the event retrieved by the trace. This function will call ``callback`` with any :class:`EventRecord` in the trace. ``begin/end`` allow to filter and only process events in a given timeframe. .. warning:: If the trace if ``REALTIME`` (no logfile) this fun

(self, callback, begin=None, end=None, context=None)

Source from the content-addressed store, hash-verified

247
248
249 def process(self, callback, begin=None, end=None, context=None):
250 """Process the event retrieved by the trace.
251 This function will call ``callback`` with any :class:`EventRecord` in the trace.
252 ``begin/end`` allow to filter and only process events in a given timeframe.
253
254 .. warning::
255
256 If the trace if ``REALTIME`` (no logfile) this function will hang/process new event until the trace is stopped.
257
258 Using ``logman -ets stop TRACE_NAME`` for exemple.
259
260 """
261 if end == "now":
262 end = gdef.FILETIME()
263 windows.winproxy.GetSystemTimeAsFileTime(end)
264 windows.utils.sprint(end)
265
266 logfile = gdef.EVENT_TRACE_LOGFILEW()
267 logfile.LoggerName = windows.pycompat.raw_decode(self.name)
268 # logfile.ProcessTraceMode = gdef.PROCESS_TRACE_MODE_EVENT_RECORD | gdef.PROCESS_TRACE_MODE_RAW_TIMESTAMP
269 logfile.ProcessTraceMode = gdef.PROCESS_TRACE_MODE_EVENT_RECORD
270 if not self.logfile:
271 logfile.ProcessTraceMode |= gdef.PROCESS_TRACE_MODE_REAL_TIME
272 else:
273 # logfile.ProcessTraceMode |= gdef.PROCESS_TRACE_MODE_REAL_TIME
274 logfile.LogFileName = self.logfile
275
276 if context:
277 context_ptr = ctypes.pointer(ctypes.py_object(context))
278 logfile.Context = ctypes.cast(context_ptr, ctypes.c_void_p)
279
280 @ctypes.WINFUNCTYPE(gdef.PVOID, PEventRecord)
281 def real_callback(record_ptr):
282 try:
283 x = callback(record_ptr[0])
284 except Exception as e:
285 print("CALLBACK ERROR: {0}".format(e))
286 return 1
287 if x is None:
288 x = 1
289 return x
290
291 @ctypes.WINFUNCTYPE(gdef.PVOID, gdef.PEVENT_TRACE_LOGFILEW)
292 def buffer_callback(trace):
293 print("Buffer-callback: event-lost={0}".format(trace[0].LogfileHeader.EventsLost))
294 print("Buffer-callback: buffer-lost={0}".format(trace[0].LogfileHeader.BuffersLost))
295 return True
296
297 logfile.EventRecordCallback = ctypes.cast(real_callback, gdef.PVOID)
298 # logfile.BufferCallback = ctypes.cast(buffer_callback, gdef.PVOID)
299 r = windows.winproxy.OpenTraceW(logfile)
300 rh = gdef.TRACEHANDLE(r)
301 return windows.winproxy.ProcessTrace(rh, 1, begin, end)
302
303 def CtxProcess(self, func, stop=False):
304 return CtxProcess(self, func, stop=stop)

Callers 1

__exit__Method · 0.45

Calls 1

castMethod · 0.80

Tested by

no test coverage detected