ETW

Event Tracing for Windows. An efficient kernel-level tracing facility that allows developers and security tools to log events from drivers and applications.

Want to actually apply concepts like this instead of just reading definitions?

Practice free on Zamlom