Introduction - If you have any usage issues, please Google them yourself
According to windows event tracking ETW (Event Trace For Windows) realize the principle of monitoring disk technology. Monitor disk read and write operations. The source code of a monitor or other-oriented. ETW can have a disk monitoring operation, file operation, the process of operation, Tcp/Udp operation and so on.
Packet : 11912886diskmontrace.rar filelist
diskmonTrace\DiskMon\DiskMon.cpp
diskmonTrace\DiskMon\DiskMon.vcproj
diskmonTrace\DiskMon\DiskMon.vcproj.PC-200807021049.Administrator.user
diskmonTrace\DiskMon\ReadMe.txt
diskmonTrace\DiskMon\stdafx.cpp
diskmonTrace\DiskMon\stdafx.h
diskmonTrace\DiskMon.sln
diskmonTrace\DiskMon.suo
diskmonTrace\DiskMon\Debug
diskmonTrace\DiskMon
diskmonTrace