Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering results, and inspecting ETL/JSON/CSV recordings from one desktop tool.
☆108Jul 27, 2026Updated 3 weeks ago
Alternatives and similar repositories for EtwSuite
Users that are interested in EtwSuite are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.☆180Jun 28, 2026Updated last month
- User-mode ETW interception and telemetry manipulation lab for Windows security research.☆44Jun 15, 2026Updated 2 months ago
- ☆64Jul 12, 2026Updated last month
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- .NET CLR-Stomping☆148May 20, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Bring your own Unwind Data Framework☆169Mar 15, 2026Updated 5 months ago
- A lexer and parser for Sleep☆21Feb 20, 2026Updated 6 months ago
- async beacon object file for notification on process creation☆17Mar 24, 2026Updated 4 months ago
- Stack spoofing Detection for CET processes by comparing shadow and user stacks.☆39May 22, 2026Updated 3 months ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 4 months ago
- A cmake template for crystal palace☆46Dec 20, 2025Updated 8 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆278Apr 16, 2026Updated 4 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆93Feb 6, 2026Updated 6 months ago
- Orchestrate detonating redteam artifacts in VMs with different EDRs to see their detection surface.☆78Aug 14, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Async BOF that notifies the operator when a user connects to a local or remote target system.☆34Jul 30, 2026Updated 3 weeks ago
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆64Jun 15, 2026Updated 2 months ago
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆46Jun 8, 2026Updated 2 months ago
- A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.☆72Nov 16, 2025Updated 9 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (D…☆138Jan 21, 2026Updated 7 months ago
- Shellcode injection using the Windows Debugging API☆182Jan 4, 2026Updated 7 months ago
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆77Jul 20, 2026Updated last month
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆157Jul 15, 2026Updated last month
- Collect Windows telemetry for Maldev☆501Aug 14, 2026Updated last week
- Linker for Beacon Object Files☆190Aug 14, 2026Updated last week
- Busybox-style Beacon Object Files for *nix post-exploitation. Reimplements common Unix utilities as BOFs for use in stripped environments…☆84Updated this week
- BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell☆134Apr 6, 2026Updated 4 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 8 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆314Aug 15, 2026Updated last week
- Proof of concept to detect module stomping detection by looking for modified .pdata sections.☆41Jun 11, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- open source implementation of the UDC2 spec used in Cobalt Strike☆59Jul 4, 2026Updated last month
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 4 months ago
- This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found …☆330May 24, 2026Updated 3 months ago
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆240Updated this week
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆99Mar 29, 2026Updated 4 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆186May 31, 2026Updated 2 months ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 8 months ago