{"_id":"@bun-win32/tdh","_rev":"3-a87a91e3b5f336424d5090652aabd1dd","name":"@bun-win32/tdh","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"@bun-win32/tdh","version":"1.0.0","keywords":["bun","ffi","win32","windows","tdh","bindings","typescript","dll"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/tdh@1.0.0","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"335296cf8f57fb4ca4c919016815fbf17ed7885b","tarball":"https://registry.npmjs.org/@bun-win32/tdh/-/tdh-1.0.0.tgz","fileCount":6,"integrity":"sha512-xiOBhb+038D6K9rIEyM2UhT2wd8WiHMS7IBCOXDik8kdcJJxNrYPYLLfvOvx2PyEc1cL0jbQ2ICOek2JYeNemA==","signatures":[{"sig":"MEUCICsqJOarTtYqN3LRO3H6E3tM5XVutHATrenKMQlYparVAiEAjDIb1MfEHFDmYOvZ8ywJHFab+coXMPCO4Yxy+OFf5iA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25530},"main":"./index.ts","type":"module","module":"index.ts","shasum":"335296cf8f57fb4ca4c919016815fbf17ed7885b","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:etw-live-monitor":"bun ./example/etw-live-monitor.ts","example:provider-explorer":"bun ./example/provider-explorer.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-xiOBhb+038D6K9rIEyM2UhT2wd8WiHMS7IBCOXDik8kdcJJxNrYPYLLfvOvx2PyEc1cL0jbQ2ICOek2JYeNemA==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/tdh"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 TDH bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.2"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/advapi32":"1.0.11","@bun-win32/kernel32":"1.0.21"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/tdh_1.0.0_1779073017190_0.8555926373573992","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@bun-win32/tdh","version":"2.0.0","keywords":["bun","ffi","win32","windows","tdh","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/tdh@2.0.0","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"6d3ce05aae31dd33c8c62ac26c31baf128a4f4b7","tarball":"https://registry.npmjs.org/@bun-win32/tdh/-/tdh-2.0.0.tgz","fileCount":6,"integrity":"sha512-b9vno6trGGbCyUAB9r7LzvEGoAyWm6qmEZZm/YN1m3MmV+41K+lgmb5ShAqQ1ScJtH4kF9Tb/7Y5RdaU+l0UFg==","signatures":[{"sig":"MEQCICiEOGghqxI4VYOX/+Cm4HwEnjrlMfO+mq2aJR6RiX5OAiA50EXa6BXKA4dIoJ6IWyTeEDboculMh4pocsDob1nYrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27185},"main":"./index.ts","type":"module","module":"index.ts","shasum":"6d3ce05aae31dd33c8c62ac26c31baf128a4f4b7","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:etw-live-monitor":"bun ./example/etw-live-monitor.ts","example:provider-explorer":"bun ./example/provider-explorer.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"_integrity":"sha512-b9vno6trGGbCyUAB9r7LzvEGoAyWm6qmEZZm/YN1m3MmV+41K+lgmb5ShAqQ1ScJtH4kF9Tb/7Y5RdaU+l0UFg==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/tdh"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 TDH bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"26.3.0","dependencies":{"@bun-win32/core":"2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/advapi32":"2.0.0","@bun-win32/kernel32":"2.0.0"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/tdh_2.0.0_1782435970330_0.612631464255962","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"author":"Stev Peifer <stev.p@outlook.com>","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dependencies":{"@bun-win32/core":"2.0.1"},"description":"Zero-dependency, zero-overhead Win32 TDH bindings for Bun (FFI) on Windows.","devDependencies":{"@bun-win32/advapi32":"2.0.1","@bun-win32/kernel32":"2.0.1","@types/bun":"latest"},"exports":{".":"./index.ts"},"license":"MIT","module":"index.ts","name":"@bun-win32/tdh","peerDependencies":{"typescript":"^5"},"private":false,"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/tdh"},"type":"module","version":"2.0.1","main":"./index.ts","keywords":["bun","ffi","win32","windows","tdh","bindings","typescript","dll"],"sideEffects":false,"engines":{"bun":">=1.1.0"},"scripts":{"example:etw-live-monitor":"bun ./example/etw-live-monitor.ts","example:provider-explorer":"bun ./example/provider-explorer.ts"},"_id":"@bun-win32/tdh@2.0.1","_integrity":"sha512-wc/pV9PbKFV6zpDgQi2Wz+haCZ2938a1Dm4Shk0XtlCnSyA26GidP+examCl28+ztaCnQlybM6EQVhcxmqxxdQ==","_nodeVersion":"26.3.0","_npmVersion":"10.8.3","shasum":"9964e5398eee96d0ebbffb71a611e7338b6e95f3","dist":{"integrity":"sha512-wc/pV9PbKFV6zpDgQi2Wz+haCZ2938a1Dm4Shk0XtlCnSyA26GidP+examCl28+ztaCnQlybM6EQVhcxmqxxdQ==","shasum":"9964e5398eee96d0ebbffb71a611e7338b6e95f3","tarball":"https://registry.npmjs.org/@bun-win32/tdh/-/tdh-2.0.1.tgz","fileCount":6,"unpackedSize":27185,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDLp/OKvBq+jITDozUE9TAH6gLK18z3QHzvyIbODqlyjgIhAO8sU4bceTH/OFrE9NR33lTvCzWaBnWdfdAyCi/YkCEx"}]},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"directories":{},"maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/tdh_2.0.1_1782438176369_0.43121727871166415"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-18T02:56:57.081Z","modified":"2026-06-26T01:42:56.611Z","1.0.0":"2026-05-18T02:56:57.333Z","2.0.0":"2026-06-26T01:06:10.500Z","2.0.1":"2026-06-26T01:42:56.509Z"},"bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","homepage":"https://github.com/ObscuritySRL/bun-win32#readme","keywords":["bun","ffi","win32","windows","tdh","bindings","typescript","dll"],"repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/tdh"},"description":"Zero-dependency, zero-overhead Win32 TDH bindings for Bun (FFI) on Windows.","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"readme":"# @bun-win32/tdh\n\nZero-dependency, zero-overhead Win32 TDH bindings for [Bun](https://bun.sh) on Windows.\n\n## Overview\n\n`@bun-win32/tdh` exposes the `tdh.dll` exports using [Bun](https://bun.sh)'s FFI. It provides a single class, `Tdh`, which lazily binds native symbols on first use. You can optionally preload a subset or all symbols up-front via `Preload()`.\n\nThe bindings are strongly typed for a smooth DX in TypeScript.\n\n`tdh.dll` is the **Trace Data Helper** — the decoding layer for Event Tracing for Windows (ETW). It turns the opaque binary `EVENT_RECORD`s delivered by an ETW session into structured, named, human-readable data, and enumerates the providers and event schemas registered on the machine. Pair it with `@bun-win32/advapi32` (`StartTrace` / `OpenTrace` / `ProcessTrace`) to build a complete trace consumer.\n\n## Features\n\n- [Bun](https://bun.sh)-first ergonomics on Windows 10/11.\n- Direct FFI to `tdh.dll` (ETW event metadata, property formatting, provider/field/event-schema enumeration, value/bitmap decoding, manifest loading, and payload filters).\n- In-source docs in `structs/Tdh.ts` with links to Microsoft Docs.\n- Lazy binding on first call; optional eager preload (`Tdh.Preload()`).\n- No wrapper overhead; calls map 1:1 to native APIs.\n- Strongly-typed Win32 aliases (see `types/Tdh.ts`).\n\n## Requirements\n\n- [Bun](https://bun.sh) runtime\n- Windows 10 or later\n\n## Installation\n\n```sh\nbun add @bun-win32/tdh\n```\n\n## Quick Start\n\n```ts\nimport Tdh from '@bun-win32/tdh';\n\n// Optionally bind a subset up-front\nTdh.Preload(['TdhEnumerateProviders']);\n\n// Two-call sizing pattern: first NULL to learn the size, then allocate.\nconst bufferSize = Buffer.alloc(4);\n\n// ERROR_INSUFFICIENT_BUFFER (122) on the sizing call is expected.\nTdh.TdhEnumerateProviders(null, bufferSize.ptr);\n\nconst buffer = Buffer.alloc(bufferSize.readUInt32LE(0));\nconst status = Tdh.TdhEnumerateProviders(buffer.ptr, bufferSize.ptr);\n\nif (status === 0) {\n  // PROVIDER_ENUMERATION_INFO: ULONG NumberOfProviders; ULONG Reserved; TRACE_PROVIDER_INFO[]\n  console.log('Registered ETW providers: %d', buffer.readUInt32LE(0));\n}\n```\n\n> [!NOTE]\n> AI agents: see `AI.md` for the package binding contract and source-navigation guidance. It explains how to use the package without scanning the entire implementation.\n\n## Examples\n\nRun the included examples:\n\n```sh\nbun run example:etw-live-monitor     # Live, color-coded ETW event stream (cross-package with advapi32)\nbun run example:provider-explorer    # Full ETW provider + event-schema enumeration report\n```\n\n## Notes\n\n- Either rely on lazy binding or call `Tdh.Preload()`.\n- Windows only. Bun runtime required.\n- **SAL types & naming:** nullability is in the **type** — `Optional<T>` (formally optional, SAL `_*opt_`) and `Nullable<T>` (plain `[in]`/`[out]` the docs say can be NULL), the null sentinel derived from `T` (`null` for pointers `LP*`/`P*`, `0n` for handles/by-value addresses); direction is in the **parameter name** — `_out` (`_Out_`), `_in_out` (`_Inout_`), `_In_` bare. See `AI.md` and the repo `AGENTS.md`.\n","readmeFilename":"README.md"}