A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #19306  by Stylo
 Fri May 17, 2013 10:16 am
Is there a tool that can capture IRP's that is free?
i saw BUSTrace but it requires a license.
any1 knows something similar ?

Thanks
 #19888  by nullandnull
 Sun Jun 30, 2013 6:34 pm
Procmon can also be used to track certain types of IRPs.

Process Monitor > Filter > Enable advance output