ProcessusT / ETWMonitor
Windows notifier tool that detects suspicious connections by monitoring ETW event logs
☆117Updated 2 years ago
Alternatives and similar repositories for ETWMonitor:
Users that are interested in ETWMonitor are comparing it to the libraries listed below
- VULNSPY regularly retrieves the latest alerts published by the CERT-FR and the related vulnerabilities with their CVSS score and allows y…☆38Updated 2 years ago
- The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.☆126Updated 4 months ago
- ☆103Updated last year
- Identify the accounts most vulnerable to dictionary attacks☆117Updated 7 months ago
- A python script to automatically list vulnerable Windows ACEs/ACLs.☆50Updated 3 months ago
- ☆174Updated 3 months ago
- GolenGMSA tool for working with GMSA passwords☆139Updated 11 months ago
- Collection of scripts to retrieve stored passwords from Veeam Backup☆122Updated 3 months ago
- Retrieve and display information about active user sessions on remote computers. No admin privileges required.☆180Updated 7 months ago
- Scripts permettant de contourner la protection antivirale de Windows Defender via la technique de Direct Syscalls avec une injection de s…☆27Updated 2 years ago
- Automatically run and populate a new instance of BH CE☆66Updated 4 months ago
- A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application☆97Updated last month
- Outil de récupération automatique des données AZure / Automated tool for dumping Azure configuration data☆18Updated 2 weeks ago
- Guide journalisation Microsoft☆60Updated 7 months ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆181Updated last month
- Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube☆84Updated 8 months ago
- Obfuscate the bytes of your payload with an association dictionary☆33Updated 3 months ago
- Finding all things on-prem Microsoft for password spraying and enumeration.☆254Updated 2 years ago
- Run Your Payload Without Running Your Payload☆180Updated 2 years ago
- Monitor your PingCastle scans to highlight the rule diff between two scans☆109Updated 7 months ago
- Detect WFP filters blocking EDR communications☆85Updated last year
- RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++☆245Updated last year
- A security assessment tool for analyzing Active Directory Group Policy Objects (GPOs) to identify misconfigurations and vulnerabilities☆206Updated 2 months ago
- Scraping Kit is made up of several tools for scraping services for keywords, useful for initial enumeration of Domain Controllers or if y…☆98Updated last year
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆93Updated last year
- A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.☆142Updated 10 months ago
- Docker images of the Exegol project☆101Updated this week
- ☆138Updated 6 months ago