Maldev-Academy / PrefetchFileParserLinks
A lightweight Windows Prefetch file parser to extract programs' execution history
☆62Updated 3 weeks ago
Alternatives and similar repositories for PrefetchFileParser
Users that are interested in PrefetchFileParser are comparing it to the libraries listed below
Sorting:
- ☆78Updated 3 years ago
- ☆108Updated last year
- ☆37Updated 2 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆65Updated 2 years ago
- Commandline spoofing on Windows☆92Updated 2 months ago
- A cmake template for crystal palace☆38Updated last month
- Template-based generation of shellcode loaders☆80Updated last year
- ☆80Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Updated last year
- Blog/Journal on how to backdoor VSCode extensions☆76Updated 6 months ago
- Just another ntdll unhooking using Parun's Fart technique☆76Updated 2 years ago
- API Hammering with C++20☆49Updated 3 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆46Updated 2 years ago
- I have documented all of the AMSI patches that I learned till now☆75Updated 3 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆42Updated 10 months ago
- ☆79Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆41Updated 2 years ago
- Some of the presentations, workshops, and labs I gave at public conferences.☆34Updated 3 months ago
- BOF to decrypt Signal Desktop chat logs☆72Updated 11 months ago
- .NET tool used to enrich RPC telemetry☆101Updated 2 weeks ago
- Toolset to manipulate RPC clients by finding delayed services and masquerading as them☆106Updated 5 months ago
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61Updated 8 months ago
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆60Updated last month
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated last year
- Win32 keylogger that supports all (non-ime using) languages correctly☆53Updated 2 years ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆48Updated 3 months ago
- Small tool to play with IOCs caused by Imageload events☆44Updated 2 years ago
- ☆55Updated 8 months ago