trace_syscalls
Generate an NT syscall/API tracing plan for a VM using ETW, WPR, or KDNET, optionally start in-guest prep via qemu-ga, and fetch results with vm_get_file.
Instructions
Write a concrete NT-syscall/API tracing plan for this VM (ETW/WPR steps, KDNET setup, static-surface fallback) and optionally kick off in-guest prep via qemu-ga.
Dynamic tracing needs in-guest tooling; this tool gives the exact commands and can fetch the results with vm_get_file afterwards.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| vm | No | ||
| workspace | No | ||
| target_app | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |