0xeb / WinTools
A collection of free miscellaneous Windows tools
☆123Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for WinTools
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆269Updated 6 months ago
- API Set Viewer☆84Updated 4 years ago
- View ETW Provider manifest☆433Updated 3 weeks ago
- Document ETW providers☆207Updated 4 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- Run Processes as PPL with ELAM☆146Updated 2 years ago
- Named pipe I/O ETW provider for Windows☆67Updated 4 years ago
- Authenticode Hash Calculator for PE32/PE32+ files☆107Updated 9 months ago
- PE Viewer☆152Updated 3 weeks ago
- Sysmon-Like research tool for ETW☆336Updated 2 years ago
- Run any executable as SYSTEM account (no service required)☆124Updated 6 months ago
- DotNext 2019 St. Petersburg Talk Demos☆36Updated 5 years ago
- ☆68Updated 2 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆254Updated 3 years ago
- A WinDbg extension to trace COM interactions☆110Updated 9 months ago
- WNF Utilities 4 Newbies (WNFUN)☆92Updated 5 years ago
- Parser to process monitor file formats☆129Updated last year
- ☆61Updated 9 months ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆135Updated 5 years ago
- RPC Monitor tool based on Event Tracing for Windows☆330Updated 3 months ago
- Windows Registry Knowledge Base☆162Updated last month
- Enhanced version of the classic Spy++ tool☆176Updated 7 months ago
- Lnk file parser☆79Updated 2 months ago
- A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policies☆201Updated 2 years ago
- Windows user-land hooks manipulation tool.☆139Updated 3 years ago
- Module to provide PowerShell functions that abstract Win32 API functions☆239Updated 5 months ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated this week
- Kernel Pool Monitor☆121Updated 2 years ago
- Expand compressed files from WinSxS folder☆146Updated 4 months ago
- Demo service that runs in svchost.exe☆79Updated 6 years ago