Maldev-Academy / PrefetchFileParserLinks
A lightweight Windows Prefetch file parser to extract programs' execution history
☆42Updated last week
Alternatives and similar repositories for PrefetchFileParser
Users that are interested in PrefetchFileParser are comparing it to the libraries listed below
Sorting:
- .NET tool used to enrich RPC telemetry☆101Updated 7 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆65Updated 2 years ago
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- ☆159Updated last year
- A BOF to enumerate system process, their protection levels, and more.☆124Updated last year
- sideloading PoC using onedrive.exe & version.dll☆88Updated 2 months ago
- I have documented all of the AMSI patches that I learned till now☆75Updated 2 months ago
- ☆80Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆51Updated last year
- ☆83Updated last year
- ☆108Updated last year
- Охотник (Hunter) is a simple Adversary Simulation tool developed for achieves stealth through API unhooking, direct and indirect syscalls…☆90Updated 8 months ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆102Updated 2 years ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75Updated last year
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆89Updated 2 years ago
- ☆55Updated 7 months ago
- BOF template with boflink and mutator kit support☆46Updated last week
- ☆109Updated 11 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated 2 years ago
- Python module for running BOFs☆79Updated last month
- Modern PIC implant for Windows (64 & 32 bit)☆105Updated 5 months ago
- Detect WFP filters blocking EDR communications☆96Updated 2 years ago
- ☆79Updated last year
- ☆32Updated last year
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Updated 9 months ago
- Tool for working with Indirect System Calls in Cobalt Strike's Beacon Object Files (BOF) using SysWhispers3 for EDR evasion☆99Updated 6 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- ☆76Updated 3 years ago
- Find DLLs with RWX section☆80Updated 2 years ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year