ProcessusT / ETWMonitorLinks
Windows notifier tool that detects suspicious connections by monitoring ETW event logs
☆124Updated 3 years ago
Alternatives and similar repositories for ETWMonitor
Users that are interested in ETWMonitor are comparing it to the libraries listed below
Sorting:
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆43Updated last year
- Finding secrets in kernel and user memory☆116Updated 2 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- Create and enumerate hidden desktops.☆88Updated 2 years ago
- ☆68Updated 3 years ago
- A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.☆41Updated last year
- Spoofing desktop login applications with WinForms and WPF☆177Updated last year
- Deleting Shadow Copies In Pure C++☆118Updated 3 years ago
- Analyse MSI files for vulnerabilities☆140Updated last year
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆137Updated 2 years ago
- Ransomware simulator written in C#☆37Updated 3 years ago
- A ProcessMonitor visualization application written in rust.☆183Updated 2 years ago
- Privileger is a tool to work with Windows Privileges☆139Updated 2 years ago
- ☆85Updated 3 years ago
- ☆107Updated 2 years ago
- Scan vulnerable drivers on Windows with loldrivers.io☆186Updated 2 years ago
- Detect WFP filters blocking EDR communications☆96Updated 2 years ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆188Updated last month
- Default Detections for EDR☆97Updated last year
- Updated version of PowerDNS by @domchell. Adds support for transfers over DNS A records and a few other useful features.☆83Updated 2 years ago
- ☆192Updated last year
- Collection of scripts to retrieve stored passwords from Veeam Backup☆142Updated 7 months ago
- ☆132Updated 2 years ago
- ☆119Updated last year
- Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell pro…☆85Updated 2 years ago
- Repository for archiving Cobalt Strike configuration☆35Updated last week
- RDLL for Cobalt Strike beacon to silence sysmon process☆91Updated 3 years ago
- A Repository to Track Anti-Forensic Techniques☆118Updated 2 years ago
- DNS Tunneling using powershell to download and execute a payload. Works in CLM.☆231Updated 3 years ago
- Execute PowerShell code at the antimalware-light protection level.☆142Updated 3 years ago