Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering results, and inspecting ETL/JSON/CSV recordings from one desktop tool.
☆94Jul 27, 2026Updated last week
Alternatives and similar repositories for EtwSuite
Users that are interested in EtwSuite are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆176Jun 28, 2026Updated last month
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆43Jun 15, 2026Updated last month
- ☆58Jul 12, 2026Updated 3 weeks ago
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- .NET CLR-Stomping☆147May 20, 2026Updated 2 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Bring your own Unwind Data Framework☆163Mar 15, 2026Updated 4 months ago
- A lexer and parser for Sleep☆21Feb 20, 2026Updated 5 months ago
- async beacon object file for notification on process creation☆17Mar 24, 2026Updated 4 months ago
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated 2 months ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- A cmake template for crystal palace☆43Dec 20, 2025Updated 7 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆277Apr 16, 2026Updated 3 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆92Feb 6, 2026Updated 5 months ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆64Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Updated this week
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆62Jun 15, 2026Updated last month
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆44Jun 8, 2026Updated last month
- A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.☆72Nov 16, 2025Updated 8 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆136Jan 21, 2026Updated 6 months ago
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 6 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆34Jul 20, 2026Updated 2 weeks ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 4 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆157Jul 15, 2026Updated 2 weeks ago
- Collect Windows telemetry for Maldev☆497Updated this week
- Linker for Beacon Object Files☆191Jul 28, 2026Updated last week
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆83Jul 5, 2026Updated 3 weeks ago
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆134Apr 6, 2026Updated 3 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 7 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Jul 5, 2026Updated 3 weeks ago
- Proof of concept to detect module stomping detection by looking for modified .pdata sections.☆41Jun 11, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- open source implementation of the UDC2 spec used in Cobalt Strike☆57Jul 4, 2026Updated 3 weeks ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 3 months ago
- This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found …☆319May 24, 2026Updated 2 months ago
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆235Updated this week
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆96Mar 29, 2026Updated 4 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆183May 31, 2026Updated 2 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 7 months ago