wtrace is a formidable system and process tracing and analysis tool. Available for Windows OS only, the tool is as simple as it gets in terms of execution and portability. More details on the wtrace project and how to get started with the application wtrace is free of cost, open-source, and mainly written in C# and F#. The developer did an excellent job at offering a non-install, portable digital asset that you can use on different Windows systems to run detailed analyses with filtered information and options to redirect outputs to a different location/process. The application can run in different modes. Preferable, you would open it using a command-line tool initiated with administrator privileges. Also, if you access the tool with no parameters or passed arguments, you risk initiating a full system scan accidentally, which can take a long time to finish. That is why, first things first, you can run the 'wtrace.exe' command followed by '—help.' As such, you will see the available options and filter the output with chosen parameters, or simply go for the type of analysis you are interested in conducting. Verifying your system's background process, connections, and RPC calls Although a super-useful application, wtrace might feel like an overwhelming environment for inexperienced users and less tech-knowledgeable individuals. Why? Because the program outputs, in great detail, information about complicated processes that run in the background, apps' calls, Remote Procedure Calls with local and, possibly, remote, sub-routine calls, etc. As such, wtrace will output valuable information, filtered data (if you know how to narrow down results), and network activity logs. Last but not least, due to the complexity of information it displays and the summary section with a process-tree display, you can see an in-depth overview of your machine's activity, identify friction points or possible threats, and if less tech-savvy, even learn more about kernel-level processes and their hierarchies or concurrent execution modes.


wtrace Features: Main Functions: ———- wtrace.exe wtrace.exe —help wtrace.exe -h Output and filtering options Filters work by including or excluding information in the output. You can include information that would normally be filtered out, if you try to trace a kernel-level process using a utility like Slacker or Fused. Filtering works with: 1. the relative path of the wtrace.exe executable 2. the hostname/IP address of the endpoint. 3. a list of protocols in use (TCP/UDP/DNS/FTP/…) You can also include UDP or TCP port information in the filter. 4. Filtering by port numbers The wtrace.exe includes information about how the endpoint was discovered by looking at your IP address, DNS requests, and NetBIOS name queries. wtrace will work both ways, with either the incoming or the outgoing port numbers. You can filter by incoming or outgoing port using the -i and -o filters, respectively. The inbound filter should be set to -i, followed by the port number. If the protocol is TCP, the filter should be set to -i TCP:27891 and if UDP, set it to -i UDP:27891. The outbound filter should be set to -o with the UDP/TCP port number. Another way to filter information is to include a protocol, such as DNS. In the -p filter, set the protocol to the DNS protocol (0x8008) and set the port to 53.

Network, Monitoring, Security and Troubleshooting Tool Combines Threads, Processes and Functions Application-Activation Tracking Resource-Allocation Tracking Memory Allocation Tracking Network Performance Monitoring PCI Scanning and Data Analysis Trends on Data Corruption App Monitoring Analysis Tracking and Tool Resource/App/PCI Logging Remotely Tracking/Posting Threads Monitoring Supporting a wide range of systems Code-Level Covers Operating systems from: Windows 98 Windows ME Windows 2000 Windows XP Windows Vista Windows 7 Windows 8 Windows 10 MacOS X Linux FreeBSD BSD OpenBSD Solaris Network FTP, Telnet, HTTP, SSH, SOCKS, POP3, IMAP, SNMP, SMTP, POP3, IMAP, SSH, SOCKS, SMTP, POP3, IMAP, SSH, SOCKS, SMTP

The program is a versatile system-analysis tool. This description is going to describe the features of the application and how to use it. The program has 4 menu interfaces: • Main Menu — Starting menu interface. • Installation Menu — An option to install the software from the local drives of your PC. • Help Menu — A simple, ready-to-use help menu. • Exit Menu — An option to terminate the software. The program allows for two types of analysis: • Over-Analyzing (Full System Analysis): The user would start the program at the folder containing the files. • Reporting: The program gives selected information (based on user-defined options and filtering) on a number of selected processes, history, network, calls, ports, etc. A detailed on how to use the application is provided. wtrace.exe Command List: The application comes with a set of commands that you can use with this tool. Here are the available commands: • wtrace.exe —help • wtrace.exe —uninstall • wtrace.exe —start • wtrace.exe —stop • wtrace.exe [parameter] [parameter] [parameter]… • wtrace.exe —noreports • wtrace.exe —overview • wtrace.exe —detail • wtrace.exe —info • wtrace.exe —network • wtrace.exe —messages • wtrace.exe —help • wtrace.exe —nospider • wtrace.exe —nomonitor • wtrace.exe —report [file/folder] The first command would be the help menu, asking for help and providing a variety of available options. The uninstall menu will uninstall the application. The start option will start the software, while the stop option will terminate it. The three parameters (parameter) menu would let you pass inputs for analysis. These inputs may include a single parameter, multiple parameters, or even omit any parameters at all to do


