Abdelrahme / WinLogHuntLinks
☆21Updated last month
Alternatives and similar repositories for WinLogHunt
Users that are interested in WinLogHunt are comparing it to the libraries listed below
Sorting:
- Small tool to play with IOCs caused by Imageload events☆42Updated 2 years ago
- ☆23Updated last year
- ☆45Updated last year
- ☆46Updated 4 months ago
- ☆30Updated last month
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated 2 years ago
- Detect Remote Local Credentials Dumping using a Shadow Snapshot☆30Updated 8 months ago
- ☆18Updated last year
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆30Updated 6 months ago
- Ghosting-AMSI☆17Updated 5 months ago
- ☆18Updated last year
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆41Updated last year
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Updated 3 years ago
- ☆74Updated 2 years ago
- Extension functionality for the NightHawk operator client☆26Updated last year
- Identifies metadata of .NET binary files.☆21Updated last year
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆52Updated 5 years ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆44Updated last year
- ☆24Updated 8 months ago
- ☆20Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆40Updated 2 years ago
- Giga-byte Control Center (GCC) is a software package designed for improved user experience of Gigabyte hardware, often found in gaming an…☆33Updated 2 years ago
- ☆29Updated 8 months ago
- ☆80Updated last year
- ☆58Updated 11 months ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated 2 years ago
- Repository of Microsoft Driver Block Lists based off of OS-builds☆40Updated last year
- idk man this was the default github name☆35Updated 2 years ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Updated 2 years ago
- ☆77Updated last year