Skip to content

Commit fa5312b

Browse files
committed
Added documents
1 parent c570bb1 commit fa5312b

File tree

2 files changed

+5
-4
lines changed

2 files changed

+5
-4
lines changed

README.md

+5-4
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ This tool is a Volatility3 plugin that scans memory dumps for Event Tracing for
2323
pip install -r requirements.txt
2424
```
2525

26-
3. Clone the ETW Scan of Volatility plugin from GitHub:
26+
3. Clone the ETW Scanner of Volatility plugin from GitHub:
2727

2828
```shell
2929
git clone https://github.com/JPCERTCC/etw-scan.git
@@ -67,12 +67,13 @@ TBA
6767

6868
#### English
6969

70-
TBA
70+
* [https://blogs.jpcert.or.jp/en/2024/11/etw_forensics.html](https://blogs.jpcert.or.jp/en/2024/11/etw_forensics.html)
7171

7272
#### Japanese
7373

74-
TBA
74+
* [https://blogs.jpcert.or.jp/ja/2024/11/etw_forensics.html](https://blogs.jpcert.or.jp/ja/2024/11/etw_forensics.html)
7575

7676
### Slides
7777

78-
TBA
78+
* CODE BLUE 2024
79+
- [Slides](docs/Event_Tracing_for_Windows_Internals.pdf)
2.91 MB
Binary file not shown.

0 commit comments

Comments
 (0)