Intro
I remember when I went to a meeting on Google Montreal about ETW and tracing on Windows. The spearker was
ETW
It is the official tool for kernel tracing in windows platform developed by Microsoft. This allows the user to see call stacks and analysis system calls.
IU for ETW
It is the ETW but with some user interface features to improve ETW.
Tutorial
Bruce Dawson have done an amazing tutorial, with videos al all here [2]
More info here
[1]here: https://msdn.microsoft.com/enus/library/windows/desktop/aa363668(v=vs.85).aspx
[2] https://randomascii.wordpress.com/2014/08/19/etw-training-videos-available-now/