ET Ducky Documentation

Complete guide to using ET Ducky for Windows Event Tracing monitoring and analysis

Getting Started

System Requirements

Installation

  1. Download the installer from the homepage
  2. Run ETDucky-Setup.msi
  3. Accept the User Account Control (UAC) prompt
  4. Follow the installation wizard
  5. Launch ET Ducky from the Start Menu
Note: ET Ducky requires administrator privileges to access Event Tracing for Windows (ETW). You'll see a UAC prompt each time you launch the application.

Using ET Ducky

Starting Monitoring

  1. Launch ET Ducky
  2. Select the ETW providers you want to monitor
  3. Click "Start Monitoring"
  4. Events will appear in real-time

AI-Powered Analysis

ET Ducky can analyze events using AI to provide insights:

Subscription Plans

Choose the plan that fits your needs:

BYOK (Bring Your Own Key): All plans support using your own API keys for AI providers, giving you full control over costs and usage.

Configuration

AI Provider Setup

To use your own API keys:

  1. Go to Settings → AI Providers
  2. Select your preferred provider (Claude, ChatGPT, or Copilot)
  3. Enter your API key
  4. Click "Save Configuration"

ETW Provider Configuration

Configure which Windows ETW providers to monitor:

Database Location

Event data is stored locally in:

%PROGRAMFILES%\ET Ducky\etwmonitor.db

Troubleshooting

Common Issues

UAC Prompt Every Launch

This is normal. ET Ducky requires administrator privileges to access ETW. You can create a scheduled task to run it elevated without prompts.

No Events Showing

AI Analysis Not Working

Application Crashes

Check the logs at:

%PROGRAMFILES%\ET Ducky\logs\
Still having issues? Contact support at [email protected] with your log files.

API Reference

Supported AI Models

Anthropic Claude

OpenAI ChatGPT

ETW Provider GUIDs

Common Windows ETW providers you can monitor:

Microsoft-Windows-Kernel-Process: {22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716}
Microsoft-Windows-TCPIP: {2f07e2ee-15db-40f1-90ef-9d7ba282188a}
Microsoft-Windows-DNS-Client: {1c95126e-7eea-49a9-a3fe-a378b03ddb4d}

Support

Need help? We're here for you: