<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: gilnett</title>
    <description>The latest articles on DEV Community by gilnett (@gilnett).</description>
    <link>https://dev.to/gilnett</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4174245%2F972c317f-3429-4eb3-b4aa-8e86b637acf9.png</url>
      <title>DEV Community: gilnett</title>
      <link>https://dev.to/gilnett</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/gilnett"/>
    <language>en</language>
    <item>
      <title>Building wstrace: A Zero-Driver Windows System &amp; API Monitor in Rust</title>
      <dc:creator>gilnett</dc:creator>
      <pubDate>Fri, 09 Oct 2026 21:51:01 +0000</pubDate>
      <link>https://dev.to/gilnett/building-wstrace-a-zero-driver-windows-system-api-monitor-in-rust-4coa</link>
      <guid>https://dev.to/gilnett/building-wstrace-a-zero-driver-windows-system-api-monitor-in-rust-4coa</guid>
      <description>&lt;p&gt;I built &lt;strong&gt;wstrace&lt;/strong&gt;, a lightweight terminal-first Windows system and API monitor written in Rust.&lt;/p&gt;

&lt;p&gt;I wanted a quick way to inspect Win32 APIs and syscalls directly from the terminal without needing to install or manage kernel drivers.&lt;/p&gt;

&lt;h3&gt;
  
  
  How it works
&lt;/h3&gt;

&lt;p&gt;&lt;code&gt;wstrace&lt;/code&gt; runs purely in user space by tapping into native Windows ETW (Event Tracing for Windows) and Win32 APIs. This keeps it safe, portable, and easy to run on any machine as a single &lt;code&gt;.exe&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;It supports two workflows:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Interactive TUI&lt;/strong&gt;: Built with Ratatui to navigate processes, search events, and filter activity live.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Headless stream&lt;/strong&gt;: Outputs directly to stdout as text or JSON for piping into scripts.
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Example: stream events as JSON&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="n"&gt;wstrace&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;--name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;myapp.exe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;--headless&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;--format&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;json&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;GitHub: &lt;a href="https://github.com/gilnett/wstrace" rel="noopener noreferrer"&gt;https://github.com/gilnett/wstrace&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Feedback, issues, and PRs are welcome&lt;/p&gt;

</description>
      <category>rust</category>
      <category>opensource</category>
      <category>cli</category>
      <category>programming</category>
    </item>
  </channel>
</rss>
