I built wstrace, a lightweight terminal-first Windows system and API monitor written in Rust.
I wanted a quick way to inspect Win32 APIs and syscalls directly from the terminal without needing to install or manage kernel drivers.
How it works
wstrace runs purely in user space by tapping into native Windows ETW (Event Tracing for Windows) and Win32 APIs. This keeps it safe, portable, and easy to run on any machine as a single .exe.
It supports two workflows:
- Interactive TUI: Built with Ratatui to navigate processes, search events, and filter activity live.
- Headless stream: Outputs directly to stdout as text or JSON for piping into scripts.
# Example: stream events as JSON
wstrace --name myapp.exe --headless --format json
GitHub: https://github.com/gilnett/wstrace
Feedback, issues, and PRs are welcome
Top comments (0)